Repository hygiene · rule repo-archived
Archived repositories under review
A Metacenta review checks this under the rule The repo under review is active. Everything below applies whether or not you ever commission one.
What this rule checks
This rule flags a repository the host reports as archived, which makes it read-only. An active repository passes. We rate it medium severity, because it changes how every other finding in the review should be read.
Why it matters
Findings against an archived repository may describe a system nobody can change, or one that has already been replaced. The worklist then points at code no team will touch.
How to fix it
Confirm the archived repo is the one intended for review. Confirm which repository is active and point the review at that one. If this one is retired on purpose, say so in the report, so readers weigh its findings accordingly.
When it is fine to leave
Reviewing a retired platform on purpose, such as before a migration or for a due-diligence record. The archive flag is then expected, and the finding only records the context.
What we need to check it
Read-only access to the repository's metadata. We use the archived flag the host reports, and nothing else.
Published rules it corresponds to
OpenSSF Scorecard, rule Maintained. Ours checks the same concern, tested differently. an archived repository takes Scorecard's lowest Maintained score; here it is reported separately, because it describes the engagement rather than the team's care.
This means our check corresponds to their rule. It does not mean the publisher reviewed or endorses it.