OWASP/threat-dragon - Open Source PR Review Scorecard

An open source threat modeling tool from OWASP

C-Rank Grade: A (Welcoming) - 65/100

External PR Merge Rate: 84%

Response Time: 14h

First Timer Success: 78%

Frequently Asked Questions

Is OWASP/threat-dragon welcoming to first-time open-source contributors?

OWASP/threat-dragon has a recorded first-timer success rate of 77.8%. Repositories ranked A typically provide actionable feedback during code reviews and actively nurture new community contributors.

How fast can I expect code review feedback on my pull request?

Maintainers in OWASP/threat-dragon respond to incoming external pull requests in approximately 14.0 hours on average. Keeping PRs focused on single tasks and ensuring tests pass helps maintainers review faster.

What does the 65.3 C-Rank™ score (A Tier) represent?

The C-Rank™ system evaluates GitHub projects on a 0–100 scale using real data: PR merge rates, review turnaround time, active maintainer presence, and first-time contributor success. A score of 65.3 places OWASP/threat-dragon in the A tier.

What is the external contributor pull request merge rate for OWASP/threat-dragon?

The external contributor pull request merge rate for OWASP/threat-dragon is 84.3%, based on public PR activity from non-core contributors.

Are there Good First Issues available in OWASP/threat-dragon?

OWASP/threat-dragon currently has 2 active issue(s) tagged with beginner-friendly labels like "good first issue", "beginner", or "up-for-grabs".

OWASP
OWASP/threat-dragonAWelcoming1.6k
GitHub
Back to Explorer
OWASP

OWASP/threat-dragon

1,565
AWelcoming(65/100)JavaScript

An open source threat modeling tool from OWASP

Compare
Jump to:

AI Maintainer Review Guidelines

Review Persona

Welcoming Community Builder

Warmth Score
8.5/10
Patience Score
8.6/10
Nitpick Rate
30%

Highly welcoming maintainers in OWASP/threat-dragon. Prompt code reviews with positive guidance for new contributors.

Top PR Submission Do's

  • Ensure code complies with the project coding style
  • Keep PRs scoped to a single concern
  • Include context and link to the related issue

Top PR Friction Pitfalls (Don'ts)

  • Do not submit PRs without linking an issue
  • Do not break existing tests without fixing them
  • Do not mix unrelated refactors in a single PR
Response Velocity
13 hours
Standard maintainer review cycle

Average Response Latency

Tracks hours until a maintainer leaves a review, comment, or PR response.

Merge Efficiency
84.3%
High acceptance rate for external PRs

External Acceptance Rate

Percentage of community pull requests successfully merged into main.

First-Timer Success
77.8%
Strong first-timer PR acceptance rate

First PR Conversion

Rate at which developers submitting their first repository PR succeed.

Active Maintainers
13 core
Highly collaborative maintainer core
Diagnostic Health HUD
84.3%
Merge Gauge
77.8%
1st-Timer
Community Vibe77/100

Embed C-Rank Badge

Show contributors that your repository actively reviews and merges external pull requests.

GetMerged C-Rank badge for OWASP/threat-dragon
[![GetMerged C-Rank](https://getmerged.abhishekco.de/api/badge/OWASP/threat-dragon)](https://getmerged.abhishekco.de/OWASP/threat-dragon?utm_source=github&utm_medium=badge)

Active Good First Issues (2)

View on GitHub

Describe what problem your feature request solves: The Trivy scan in the housekeeping action was happy to report no CVE findings, whereas the Trivy scan in the pull requests was reporting CVEs for some time Describe the solution you'd like: Work out why Trivy was passing in one workflow and flagging CVEs in another workflow Provide explanation and fix if necessary Declaration: By submitting this issue you have: read the contribution guide and agree to the Code of Conduct not used agentic or generative AI in creating this feature request Additional context: This is a great first issue for someone! If you are new to Threat Dragon, reading the docs and understanding the code is a great first step! You are also uniquely qualified to find blind-spots in the documentation as you fix this. 😎 This should not be done using Generative AI or an agent. "Good first issues" are meant for our human friends to learn and start participating. If you have questions after being assigned the issue,

📅 Opened Apr 10, 2026💬 5 comments
Quality: 70/100Contribute

Describe what problem your feature request solves: The documentation does not have a "quick start" guide for new users Describe the solution you'd like: The documentation should provide a "quick start" guide for new users to help them quickly start using Threat Dragon, draw diagrams and add threats Ideally it will be a new page at the top level in the documentation : https://www.threatdragon.com/docs/ Declaration: By submitting this issue you have: read the contribution guide and agree to the Code of Conduct not used agentic or generative AI in creating this feature request Additional context: This is a great first issue for someone! If you are new to Threat Dragon, reading the docs and understanding the code is a great first step! You are also uniquely qualified to find blind-spots in the documentation as you fix this. 😎 This should not be done using Generative AI or an agent. "Good first issues" are meant for our human friends to learn and start participating. If you have ques

📅 Opened Apr 1, 2026💬 8 comments
Quality: 80/100Contribute
Looking for more JavaScript beginner tasks?Explore JavaScript GFI

Contributor Community Vibe Feedback

Rate what actually matters after opening a pull request here.

Have you contributed to this repo?

Rate your first-hand PR experience (review speed, maintainer responsiveness, and onboarding ease) to help other contributors.

3 ratings required
Maintainer helpfulness
Review speed
Beginner friendliness

Contributor Compatibility & Review Speed Analysis for OWASP/threat-dragon

When evaluating whether to contribute to OWASP/threat-dragon, response velocity and maintainer engagement are crucial. GetMerged continuously tracks pull request trajectories, first-comment latency, and code review rounds to help developers avoid submitting pull requests to backlogged repositories.

Currently, maintainers of OWASP/threat-dragon acknowledge new external contributions in approximately 13 hours. Out of all submitted pull requests from non-core authors in the last 180-day window, 84.3% were successfully merged into the primary branch.

Frequently Asked Questions - Contributing to OWASP/threat-dragon

01

Is OWASP/threat-dragon welcoming to first-time open-source contributors?

OWASP/threat-dragon has a recorded first-timer success rate of 77.8%. Repositories ranked Welcoming typically provide actionable feedback during code reviews and actively nurture new community contributors.

02

How fast can I expect code review feedback on my pull request?

The initial maintainer response time averages ~13 hours. Keeping PRs scoped to single concerns and ensuring CI checks succeed will optimize review turnaround.

03

What does the 65.3 C-Rank™ score represent?

The C-Rank™ index scores repositories on a 0 to 100 scale using an objective formula: external PR merge rates, initial response speed, active maintainer count, and first-time contributor retention. A score of 65.3 places OWASP/threat-dragon in the Welcoming tier.

04

What is the external contributor pull request merge rate for OWASP/threat-dragon?

The external pull request merge rate is 84.3%. GetMerged isolates non-core community contributions so external developers get an accurate benchmark of PR acceptance probability.

05

Are there beginner Good First Issues open in OWASP/threat-dragon?

Yes, OWASP/threat-dragon currently has 2 active issue(s) tagged with beginner-friendly labels. You can inspect these directly from the repository issues tab.

GetMerged C-Rank™ Indexing Standard

All metrics displayed for OWASP/threat-dragon are automatically retrieved via the public GitHub API and recalculated daily. Insider pull requests submitted by repository owners or organization members are excluded from merge rate calculations to preserve objective external contributor statistics.