See if there's any value in adding Allstar from the OpenSSF. It's part of the Scorecard project, but I don't know if the Scorecard automatically uses it under the hood.