Skip to content
Open {re}Source
10Resources

Tools

Tools for finding work, checking a project’s health, licensing, securing, releasing and funding it. Each entry has one line on what it does; Links were checked in October 2026.

Know a tool that belongs here? Suggest it in the Open {re}Source discussions.

Automation#

  • actions/first-interaction – Posts a welcome message on a contributor’s first issue or PR.
  • actions/labeler – Labels PRs from the paths they touch.
  • actions/stale – Marks inactive issues and PRs as stale, then closes them.
  • GitHub CLI – GitHub from the terminal: PRs, issues, releases and the API (`gh`).
  • Probot – Framework for building GitHub Apps in Node.js.
  • Todoctor by Azat S. – Tracks `TODO` comments in JavaScript and TypeScript repositories and charts them by type, with a table of every occurrence.

Community#

  • All Contributors – A bot and a spec to credit every kind of contribution in your README, not only code.
  • Better GitHub Co-Authors by Chris Swithinbank – Browser extension that adds an "Add co-authors" button to the PR merge UI, collecting every participant as a "Co-authored-by" trailer. It credits reviewers and commenters, not only code contributors.
  • Contributor Covenant – The most adopted code of conduct, with translations.
  • Discourse – Forum software, open source and self-hostable, for long conversations and support.
  • giscus – Comments for your site, stored in GitHub Discussions.
  • Zulip – Open source chat organized in topics, so threads stay readable.

Docs and sites#

  • cspell – Spell checker for code and docs, with a project dictionary for names and terms.
  • DocSearch – Algolia’s free search for open source documentation sites.
  • Docusaurus – Meta’s React-based docs framework, with versioning and a blog.
  • lychee – Fast link checker for Markdown and HTML, with a GitHub Action.
  • MkDocs – Python static site generator for docs. The core project’s last commit dates from October 2025; Material for MkDocs is the usual theme.
  • Pagefind – Static search that runs on the built site, with no server.
  • Starlight – Documentation theme for Astro, with navigation, search and i18n built in.
  • VitePress – Vue-powered static site generator for docs, from Markdown.

Finding work#

  • CodeTriage – Subscribe to a repository and get open issues by email to triage or fix.
  • ecosyste.ms – Open datasets and tools on packages, repositories and funding, to find critical projects that need help.
  • goodfirstissue.dev – Good first issues from popular repositories, filtered by language and topic.
  • OSS Insight – Trends, rankings and contributor analytics for GitHub repositories, built on GH Archive.
  • Up For Grabs – Projects that tag issues for newcomers, each with the label to search for.

Funding#

  • FUNDING.yml – The file that adds a Sponsor button to your repository and points to your funding pages.
  • GitHub Sponsors – Recurring and one-time sponsorships.
  • Open Collective – Transparent funding for a project or a group, with a public ledger and a fiscal host.
  • Polar – Sponsorships, funded issues and paid benefits for maintainers.
  • SponsorKit – Generates an image of your sponsors from several platforms, for a README. Read our article.
  • thanks.dev – Splits a monthly amount across the open source dependencies your projects use.

Repository health and stats#

  • contrib.rocks – An image of a repository’s top contributors to embed in its README. Read our article.
  • deps.dev – Google’s view of a package: versions, dependency graph, advisories, licenses and Scorecard results.
  • Libraries.io – Search packages across ecosystems and see who depends on them.
  • OpenSSF Scorecard – Automated checks on the security practices of a repository, scored from 0 to 10.
  • Repobeats – An image of a repository’s recent activity to embed in its README. Read our article.
  • Star History – Star growth charts for one or several repositories, as an image or an embed.

Licensing#

  • Choose a License – GitHub’s plain-language guide to picking a license, with a summary of each common one.
  • FOSSA – Commercial license compliance and dependency scanning.
  • license-checker-rseidelsohn – Lists the licenses of every npm dependency. The maintained fork of `license-checker`, whose last commit dates from January 2024.
  • licensee – The Ruby library GitHub uses to detect which license a repository has.
  • OSS Review Toolkit – Analyzes dependencies, scans them and produces a compliance report and an SBOM.
  • REUSE – A specification and a lint tool (`reuse lint`) to declare the license and copyright of every file.
  • ScanCode Toolkit – Scans source code for licenses, copyrights and dependencies, offline.
  • SPDX License List – The standard identifiers to use in `LICENSE` metadata, with the full text of each license.

Local AI#

Releases#

  • Changesets – Contributors add a small file per change; the release bumps versions and writes the changelog. Built for monorepos.
  • GitHub generated release notes – Release notes built from merged PRs, grouped by label with a `.github/release.yml` file.
  • Keep a Changelog – A format for human-written changelogs: one section per version, grouped by kind of change.
  • release-please – Opens a release PR from your Conventional Commits, then tags and publishes on merge.
  • semantic-release – Fully automated versioning and publishing, driven by commit messages.

Security#

  • CodeQL – GitHub’s code scanning: finds vulnerabilities by querying your code as data.
  • Dependabot – GitHub’s alerts and automatic update PRs for vulnerable or outdated dependencies.
  • Gitleaks – Finds secrets in a repository and its history, as a CLI or a pre-commit hook.
  • Grype – Scans an image, a directory or an SBOM for known vulnerabilities. Pairs with Syft.
  • OSV-Scanner – Matches your lockfiles against the OSV vulnerability database.
  • Renovate – Dependency update PRs with grouping, schedules and presets, on GitHub, GitLab and others.
  • Socket – Flags risky behavior in the packages you add (install scripts, network access, typosquats) before you merge.
  • StepSecurity Harden-Runner – Restricts and audits the network calls of a GitHub Actions runner.
  • Syft – Generates an SBOM from a directory, a container image or an archive.

Social#

  • Bluesky starter packs – Lists of accounts that a newcomer follows in one click, a way to gather a community. Read our article.
  • OpenGraph.xyz – Previews how a link looks when shared on social networks, and checks its meta tags.
  • Shields.io – Badges for READMEs: build status, version, downloads, sponsors.
  • Slidev – Slides from Markdown, for developers. Exports to PDF, which is how we make LinkedIn carousels. Read our article.