

That’s fair, and it’s a real limit of measuring GitHub config. If a team runs review or merge gating in a separate tool, or mirrors to GitHub from somewhere that’s their actual source of truth, the scan won’t see it and they’d look unprotected when they aren’t. The finding is really about repos where GitHub is the place the work happens, and even then it’s public repos only. Worth saying plainly so the number isn’t read as more than it is.

Don’t have data to answer that, but it’s a very good question. Weighting it by the number of contributors would make the data more honest, and probably more interesting. Will consider a follow-up based on this angle - thanks!