Concepts

Signals, not warranties

What an inspect.software result does and does not claim — the honest boundary between visible practice signals and a formal audit or guarantee.

Methodology v1.13.0Updated 2026-07-22

Every report, badge, and certification published by inspect.software carries the same disclaimer: results are signals, not warranties. This page states precisely what that means, because trust in the record depends on never claiming more than the evidence supports.

What a result claims

A health index and its underlying metrics reflect publicly visible practice: commit and release history, contributor distribution, community files, CI and test configuration, registry publishing state, and security-relevant signals such as those measured by the OpenSSF Scorecard. Every claim is:

  • Observable — derived from public data anyone can fetch.
  • Reproducible — every metric echoes its inputs, and the formulas are published in the methodology.
  • Versioned — each report records the metrics version it was produced under, so a result can be re-derived later.

What a result does not claim

  • It is not a code audit. No line-by-line review of correctness, performance, or vulnerability is performed. A project with exemplary process can still ship a defect.
  • It is not a security guarantee. Security posture measures visible security hygiene — it cannot rule out an undiscovered vulnerability or a compromised maintainer account.
  • It is not a judgement about a person or country. High-Risk Jurisdiction Exposure routes policy-defined public profile evidence into enhanced review. It does not determine nationality, citizenship, trustworthiness, sanctions status, repository permissions, or malicious intent.
  • It is not an endorsement. Inclusion in the public record means a repository was inspected, not that inspect.software recommends it.
  • It is not a ranking. Two records can be read side by side — the comparison view exists for exactly that — but the index weighs categories that different projects have different and legitimate reasons to answer differently. A comparison is a reading, not an order of merit.
  • It is not a prediction. A well-maintained project can be abandoned next month. Scores describe the observable present and recent past.
Certifications are signals, not warranties. They inform review and procurement; they do not replace expert judgement, legal review, or an independent security assessment where one is required.

Why this boundary is kept strict

The value of the record comes from its restraint. A registry that overstated its results would be gamed by marketing and discounted by engineers; one that states exactly what it measures can be relied on for exactly that. The same restraint appears in the formulas themselves: missing data is excluded and weights renormalized — never guessed, never counted against a project (see the health index).

Independence

Published results are independent of payment. Free public-interest scans and paid certifications run the same versioned methodology, and no commercial relationship — sponsorship, certification fees, vendor alignment — can alter a published value. Where a scan intentionally narrows the methodology, the report says so explicitly (see scan configuration).