The 20-Minute GitHub Due Diligence Checklist for Startup Investors
A five-check GitHub due-diligence checklist for investors: org pulse, commit-cadence slope, contributor trend, repository events, and release discipline, what each finding means, and the four traps that fool casual readers.
Key Takeaway
GitHub diligence in 20 minutes: org pulse, weekly cadence slope, contributor trend, new-repo events, and release discipline, each mapped to its investment-case meaning, from pre-round buildout to cadence cliffs. Includes the four failure modes (single-repo reads, star gravity, hack-week spikes, unnormalized comparison) and how checklist findings become founder-conversation questions.
Most investors look at a startup's GitHub once, count stars, and move on. A structured read takes 20 minutes and produces better questions for the founder conversation than any deck. This guide gives the exact checklist: what to open, what to compute, and what each answer means for the investment case, with the failure modes that fool casual readers.
The 20-minute GitHub due-diligence checklist#
Open the org, not a single repo, and work through five checks:
- Org pulse. Repositories, total and active in 90 days. A healthy building company has most engineering in few repos; a sprawl of dormant repos suggests abandoned experiments.
- Commit cadence by week, last 12 weeks. You want the slope, not the level: flat-high is steady state, rising is acceleration, cliff-drops pre-date layoffs or pivots more often than rewrites.
- Contributors active per week and their trend. Contributor growth beyond the founding team is the single most expensive thing to fake sustainably.
- Repository events. New repos in the last 60 days: integration, SDK, and infra repos clustering together is the classic pre-round buildout.
- Issue and release cadence. Releases shipping on a stable cadence with issues closing indicate operating discipline, not launch theater.
Score what you find; the deal flow scoring framework shows how engineering evidence slots into a four-factor scorecard, and the technical due diligence guide goes deeper per check.
What each finding means#
Rising cadence plus contributor growth plus new-repo clusters reads as preparation: hiring, building toward a launch, frequently a round. Flat everything reads as steady state, neutral for survival, uninformative for timing. Cadence cliff plus contributor drop is the strongest negative observable in public data, it precedes trouble announcements by months. High stars plus low cadence is marketing-ahead-of-product: discount the stars entirely.
Failure modes that fool casual readers#
Four traps. Single-repo reads: the flagship repo can be quiet while the real build happens in new repos, always read the org. Star gravity: stars are lagging marketing metrics. Hack-week spikes: a one-week velocity burst without breadth is noise, multi-metric confirmation is the defense. And unnormalized comparison: an AI startup and an enterprise SaaS company at the same stage have different baselines, use stage and sector benchmarks before judging either.
From checklist to founder conversation#
The checklist's output is not a verdict, it is questions. New SDK repos with no launch: what ships next quarter. Contributor growth ahead of announced hiring: how are you recruiting. Cadence flat while the deck claims hypergrowth: where does the claimed growth live. Founders respond visibly better to evidence-based questions than to generic diligence theater, and the answers are checkable against the public record.
Key takeaways#
Read the org, not the repo; read slopes, not levels; require multi-metric confirmation; normalize by sector and stage. Twenty minutes on the public record produces founder questions that decks cannot rehearse away, and the cadence cliff is the single most actionable negative observable in public data.
Beyond engineering: corroborating layers#
The GitHub read is strongest when it fails or passes alongside other layers. Corroborate with hiring: engineering postings appearing while contributor count rises confirms growth is real and budgeted. Corroborate with product: a changelog that ships on the same cadence as the commits indicates the activity reaches users rather than accumulating in branches. Corroborate with the round record: acceleration with no round following is common and fine; the investor mistakes guide quantifies how often signals fire without events, which is exactly the base rate you need before treating a pass or a pursue as evidence-based. Multi-layer confirmation is the whole game: any single observable can be produced by causes unrelated to the investment case, but cadence, contributors, hiring, and shipping moving together has few innocent explanations.
When to walk away#
Two public-data patterns justify walking away before any call. The sustained cliff: commits and contributors falling together across a quarter, which in the tracked panel precedes public trouble by months. And the hollow graph: stars and forks accumulating while cadence stays flat and issues rot, the signature of marketing-ahead-of-product. Neither is proof; both shift the burden of proof to the founder conversation, and if the conversation does not dissolve the pattern, the pattern wins. Discipline here saves more capital than any positive screen earns, because the cost of a zero is total.
Turning the checklist into a habit#
The checklist takes twenty minutes and repays it in better founder conversations. The habit that makes it compound: file every read, verdict plus date, in the pipeline log, so your personal base rates accumulate. After a quarter you stop needing borrowed benchmarks, because you own something better, your own distribution of what acceleration looked like in the deals you won, the ones you lost, and the ones you passed on. That owned distribution is the difference between an investor who reads GitHub and an investor whose GitHub reads are evidence.