Every report, badge, and certification published by inspect.software carries the same disclaimer: results are signals, not warranties. This page states precisely what that means, because trust in the record depends on never claiming more than the evidence supports.
What a result claims
A health index and its underlying metrics reflect publicly visible practice: commit and release history, contributor distribution, community files, CI and test configuration, registry publishing state, and security-relevant signals such as those measured by the OpenSSF Scorecard. Every claim is:
- Observable — derived from public data anyone can fetch.
- Reproducible — every metric echoes its inputs, and the formulas are published in the methodology.
- Versioned — each report records the metrics version it was produced under, so a result can be re-derived later.
What a result does not claim
- It is not a code audit. No line-by-line review of correctness, performance, or vulnerability is performed. A project with exemplary process can still ship a defect.
- It is not a security guarantee. Security posture measures visible security hygiene — it cannot rule out an undiscovered vulnerability or a compromised maintainer account.
- It is not a judgement about a person or country. High-Risk Jurisdiction Exposure routes policy-defined public profile evidence into enhanced review. It does not determine nationality, citizenship, trustworthiness, sanctions status, repository permissions, or malicious intent.
- It is not an endorsement. Inclusion in the public record means a repository was inspected, not that inspect.software recommends it.
- It is not a ranking. Two records can be read side by side — the comparison view exists for exactly that — but the index weighs categories that different projects have different and legitimate reasons to answer differently. A comparison is a reading, not an order of merit.
- It is not a prediction. A well-maintained project can be abandoned next month. Scores describe the observable present and recent past.
Why this boundary is kept strict
The value of the record comes from its restraint. A registry that overstated its results would be gamed by marketing and discounted by engineers; one that states exactly what it measures can be relied on for exactly that. The same restraint appears in the formulas themselves: missing data is excluded and weights renormalized — never guessed, never counted against a project (see the health index).
Independence
Published results are independent of payment. Free public-interest scans and paid certifications run the same versioned methodology, and no commercial relationship — sponsorship, certification fees, vendor alignment — can alter a published value. Where a scan intentionally narrows the methodology, the report says so explicitly (see scan configuration).