Mar 20, 2026 at 6:04 AM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
high23 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

3 of 3 sub-signals with data

Known CVEs40%5.0

No known CVEs

via OSV.dev

Dependency Health30%3.0

90 dependencies (moderate)

via npm / PyPI

Supply Chain30%5.0

Supply chain analyzed, no transitive CVEs

via npm provenance

Uptime, latency, error rates, and incident history

4 of 4 sub-signals with data

Uptime35%5.0

100.00% over 6 checks

via Health checks

Response Latency25%5.0

p99: 33ms, p50: 16ms

via Health checks

Error Rate20%5.0

0.00% error rate (0/6)

via Health checks

Incident History20%3.0

2 incidents in last 90 days

via Incidents table

Commit recency, release cadence, issue response, CI/CD

4 of 4 sub-signals with data

Commit Recency30%5.0

via GitHub

Release Cadence25%3.0

via GitHub

Issue Response20%1.0

via GitHub

CI/CD Presence25%5.0

via GitHub Actions

Downloads, stars, dependents, and growth trajectory

1 of 4 sub-signals with data

Download Volumeno data

Weight redistributed to sub-signals with data

GitHub Stars100%5.0

32,898 stars

via GitHub

Dependent Packagesno data

Weight redistributed to sub-signals with data

Growth Trendno data

Weight redistributed to sub-signals with data

License, documentation, security policy, changelog

4 of 4 sub-signals with data

Open Source30%5.0

Public repo with OSI-approved license (apache-2.0)

via GitHub

Documentation25%5.0

Docs site present with comprehensive README (>2000 bytes + examples)

via GitHub

Security Policy20%2.0

No SECURITY.md found

via GitHub

Changelog25%4.0

Releases exist but no CHANGELOG.md

via GitHub

Track record, org maturity, community standing

4 of 4 sub-signals with data

Track Record35%1.0

First service for publisher

via Fabric index

Org Maturity25%5.0

Organization, 9.0 years old

via GitHub

Community Standing20%5.0

385 public repositories

via GitHub

Cross-Platform20%3.0

Present on 2 platform(s): github, pypi

via Registry scan

About this score
Scored across 23 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment

Diffusers is a PyTorch and JAX library for state-of-the-art diffusion models, published by the Hugging Face team under Apache 2.0 license. The package shows strong adoption metrics and zero known CVEs, indicating low risk detected for production use. With 90 dependencies including ML infrastructure packages like accelerate and safetensors, teams should monitor the dependency tree for supply chain considerations.

Generated by Fabric AI · Mar 4, 2026 at 4:10 AM

Package Availability (30d)
100.00%
p50: 16ms · p99: 33ms
Avg Latency
17ms
averaged across 30d health checks
Weekly Downloads
no package registry data
Incidents & Alertslast 90 days
Mar 1Trust score decreased by 1.273.24
Feb 22diffusers added to Trust Index3.40
Showing 2 of 2 events
Score History90 snapshots
5.003.752.501.250.00
Feb 22Feb 26
Supply Chain & Dependenciestrust chain
accelerate
pypi · >=0.31.0; extra == "dev"
bitsandbytes
pypi · >=0.43.3; extra == "bitsandbytes"
compel
pypi · ==0.1.8; extra == "dev"
datasets
pypi · *
filelock
pypi · * · 2 CVEs
flax
pypi · >=0.4.1; extra == "dev"
Showing 6 of 45 dependencies
Data Sources6 indexed
Version History
VERSIONRELEASED
v0.36.0Dec 8, 2025
v0.35.2Oct 15, 2025
v0.35.1Aug 20, 2025
v0.35.0Aug 19, 2025
v0.34.0Jun 24, 2025
v0.33.1Apr 10, 2025
Showing 6 of 10 releases

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card