Discover projects looking for contributors, reviewers, maintainers, and documentation help.
Find where you can help. Understand why it matters.
Features · How it works · Quick start · Development · Operations
Your next contribution could be a first pull request, a documentation fix, a review, or a long-term maintainer role. maintain.help brings those opportunities together, with source links and activity signals that explain why a project appears.
Explicit requests, inferred capacity pressure, and verified maintainer updates each carry their own context. You can read the evidence before deciding where to spend your time.
| Find your next contribution | |
|---|---|
| ⌕ Explore | Browse projects seeking maintainers, asking for help, or looking for documentation and PR review support. |
| ↗ Find a match | Filter by your languages, the kind of help you want to give, and your experience level. |
| ◎ See the evidence | Inspect source links, confidence levels, activity charts, and open opportunities. |
| + Add a project | Submit a GitHub repository for analysis and discovery. |
| ♡ Keep a shortlist | Sign in with GitHub to save repositories and return to them later. |
| ✓ Speak as a maintainer | Verify your repository permissions, claim a project, and state what help you need. |
GitHub repository Evidence & activity A place to contribute
───────────────── ────────────────── ─────────────────────
README / CONTRIBUTING Explicit requests Help categories
Issues / discussions → Capacity signals → Status & confidence
Pull requests / commits Beginner friendliness Source links & matches
The analysis uses explainable rules to combine maintainer statements, issue labels, backlogs, and contributor activity. Results include the signals behind them.
| Status | What it means |
|---|---|
| Seeking maintainers | An explicit request for maintainers, co-maintainers, or a successor. |
| Actively asking | A direct request for help or open issues with contribution labels. |
| Likely needs help | Activity suggests capacity pressure; the result carries an inferred confidence level. |
| Maintenance mode | The repository declares maintenance mode or GitHub marks it as archived. |
| Healthy | The analysis found no significant capacity pressure, or the maintainer says they are not looking for help. |
Maintainers have the final say. A verified maintainer's self-reported status takes precedence over the automated classification.
Use Node.js 22.12+ in the 22.x line, or Node.js 24+, npm, a PostgreSQL database, and a Clerk application with GitHub sign-in enabled.
git clone https://github.com/byalex33/maintain.help.git
cd maintain.help
npm ciCopy .env.example to .env, then fill in your credentials.
| Variable | Purpose |
|---|---|
DATABASE_URL |
PostgreSQL connection string. |
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY |
Clerk's browser-safe publishable key. |
CLERK_SECRET_KEY |
Clerk's server-side secret key. |
GITHUB_ANALYSIS_TOKEN |
Server-side GitHub token for public repository ingestion. |
PRISMA_DEV_DATABASE |
Set to true only for the embedded prisma dev database; otherwise leave false. |
ADMIN_GITHUB_IDS |
Comma-separated numeric GitHub user IDs allowed to use admin tools. |
CRON_SECRET |
Bearer secret for scheduled analysis requests. |
In Clerk, enable GitHub only and disable other sign-in methods. See the authentication notes below for production setup and repository claims. Local .env files are ignored by Git.
Admin access uses numeric GitHub IDs because usernames can be renamed and reused. Find an ID at https://api.github.com/users/<login> (the id field). ADMIN_GITHUB_LOGINS is no longer read: existing deployments must set ADMIN_GITHUB_IDS, or admin tools stay locked.
npm run db:migrate
npm run db:generate
npm run db:seed
npm run devOpen localhost:3000. The seed command adds development fixtures so you can explore the interface immediately. Add a repository to analyze live GitHub data.
Using the embedded local database
Run npm run db:dev in a separate terminal. Copy its TCP database URL into DATABASE_URL and set PRISMA_DEV_DATABASE="true" before preparing the database.
This flag configures one connection per process and promptly closes idle connections. Prisma v7's pg adapter needs these pool options explicitly; the old connection_limit URL parameter does not configure its pool. Restart Next.js after changing the flag.
If builds or restarts lead to Connection terminated unexpectedly, stop the embedded server with npx prisma dev stop default, then restart it with npm run db:dev. Its socket layer can retain stale connection slots while the port is still listening. Restarting preserves data; do not reset or remove the database.
| Command | What it does |
|---|---|
npm run dev |
Start the Next.js development server. |
npm test |
Run the Vitest test suite. |
npm run test:watch |
Run tests in watch mode. |
npm run typecheck |
Check TypeScript types. |
npm run lint |
Run ESLint. |
npm run build |
Build the production application. |
npm start |
Serve the production build. |
npm run analyze:repo -- owner/repo |
Ingest one repository and print its analysis. |
npm run calibrate:ingest |
Ingest the controlled repository set in scripts/calibrate-ingest.ts. |
Next.js App Router · React · TypeScript · Tailwind CSS · Radix UI · Recharts
PostgreSQL · Prisma · Clerk · Octokit · Vitest
src/
├── app/ Pages, server actions, and API routes
├── components/ Discovery, repository, authentication, and UI components
└── lib/
├── detection/ Evidence, metrics, scoring, and classification
├── github/ GitHub data, discovery, and permissions
└── queries/ Repository browsing and matching
prisma/ Schema, migrations, and development fixtures
scripts/ Repository analysis and calibration tools
tests/ Authentication, detection, GitHub, and validation tests
Vercel omits sensitive secret values from environment exports. Check the project environment metadata and authenticated runtime behavior before treating an empty exported value as a missing secret.
Authentication & repository claims
/sign-in uses Clerk's UI components, and src/proxy.ts establishes sessions. Discovery is public; server actions and API routes enforce permissions for protected operations. GitHub sign-up uses the same screen.
Claim checks retrieve the current user's GitHub OAuth token from Clerk on the server. Keep GITHUB_ANALYSIS_TOKEN separate: it handles public repository ingestion and never substitutes for user permissions. Only the Clerk publishable key belongs in browser code.
A claim stays verified for 90 days (CLAIM_VALIDITY_DAYS in src/lib/claims.ts). Resubmitting the claim form re-checks GitHub access and renews it. After that, the maintainer's status stops overriding inference at the next reanalysis, the verified banner is hidden, and their feedback is no longer trusted. Feedback and reports allow one open item per type, repository and user, and 10 submissions per user in any 24 hours.
For production, create a Clerk production instance, configure the maintain.help domain and GitHub connection using Clerk's callback URL, and set that instance's keys in the hosting environment. Clerk's development GitHub connection uses shared credentials by default. Do not add private-repository scopes for public discovery; organization OAuth policies can still require an owner to approve claim checks.
Existing installations: the Clerk migration adds a nullable, unique User.clerkId. On first sign-in, the verified GitHub numeric ID links the existing local user, preserving saves, claims, and reviews. Email and username are never used to merge accounts. Legacy authentication tables remain inert; old sessions, stored OAuth tokens, and NextAuth environment variables are no longer used. A GitHub identity linked to a different Clerk user fails closed and requires deliberate administrative reconciliation.
Admin tools & scheduled analysis
| Route | Access and purpose |
|---|---|
/admin |
Repository moderation for users in ADMIN_GITHUB_IDS: search listings, view reports, lock/unlock, delete/restore. |
/admin/calibration |
Redirects to /admin. |
/api/admin/ingest |
Admin-only ingestion of a bounded repository list or GitHub search query. |
/api/cron/analyze-repositories |
Scheduled analysis; requires Authorization: Bearer $CRON_SECRET. |
vercel.json configures the analysis cron to run every six hours.
Successful analyses are reused for one hour. Database leases prevent concurrent imports of the same repository, and failed analyses retry with a one-to-24-hour backoff. Apply migrations before running the updated ingestion pipeline.
For optional database checks, set TEST_DATABASE_URL to a migrated test database and run npm test. Native PostgreSQL runs the concurrency checks; the embedded development database runs the single-session lease check and skips multi-session locking tests.
Production database & build
Configure the production database and authentication environment, leave PRISMA_DEV_DATABASE false, then run:
npx prisma migrate deploy
npm run db:generate
npm run build
npm startThe development fixture seed is optional for local exploration and is not part of the production setup.
Open source runs on people who show up.
Find a project. Lend a hand.