Skip to content
CAI
Software that uses CAICheck a score

Badge & mark usage

A badge that points to proof.

A badge on a repository is a claim, and this policy exists so the claim can be checked in one click. It is short, and it is the whole policy: a badge links to the signed survey it stands for, names the rubric version that survey was scored under, and takes anyone who follows it to both the number and the person who issued it.

Embed it

The badge comes from the standard; the survey it stands for comes from the issuer. The image is rendered here, from the issuer's published evidence, folded through the reference scorer under the rubric that evidence names — so the number on it is one you can work out again yourself, not one taken on trust from whoever was measuring. One renderer also means a CAI badge looks like a CAI badge whoever surveyed you, which matters more with every new implementation.

Replace HOST with the git host your repository lives on (github, gitlab, bitbucket or azuredevops), OWNER/REPO with your repository, and ISSUER-HOST in the link with your issuer's host. The host is part of the address because an owner and a name are not an identity: the same pair can be a different project on a different git host. There is one issuer today, Watchdog, at app.watchdog.canine.dev; name another with ?issuer= once there is one. A repository with no published survey gets no badge — a 404 rather than a zero, because a zero for something nobody measured reads as a verdict.

Markdown

[![CAI](https://app.codeassuranceindex.info/api/badge/HOST/OWNER/REPO.svg)](https://ISSUER-HOST/api/oss/OWNER/REPO/report)

HTML

<a href="https://ISSUER-HOST/api/oss/OWNER/REPO/report">
  <img src="https://app.codeassuranceindex.info/api/badge/HOST/OWNER/REPO.svg" alt="CAI">
</a>

reStructuredText

.. image:: https://app.codeassuranceindex.info/api/badge/HOST/OWNER/REPO.svg
   :target: https://ISSUER-HOST/api/oss/OWNER/REPO/report
   :alt: CAI

The rules

The three rules.

A badge links to the one specific signed survey it stands for, so the number on it always has a record behind it that somebody can open and read.

Must state the rubric version

A number means one thing under one version of the rules and something slightly different under the next. A published rubric version never changes afterwards, so naming it is what lets the score be worked out again exactly as it was.

Must not imply certification

A CAI score is a measurement taken under a stated version of the rules, with a record anyone can open. A badge says exactly that much and stops there. The words certified, approved and guaranteed claim something the standard does not grant, and a badge using them is making a claim of its own.

The badge image and the address it comes from belong to whoever issued the survey. The policy above belongs to the standard, so every issuer's badge is held to the same bar. Today that means Watchdog, which is the only issuer so far, and a second one inherits these same three rules on its first day. A badge you cannot follow through to a survey you can check is not a CAI badge.

A badge and the CAI-measured mark are different things.

A badge belongs to a codebase and carries its CAI score. The CAI-measured mark belongs to a static-analysis tool, and says that tool's false-positive rate was measured under the published method rather than quoted by its vendor. The noise standard explains the mark and how it is earned.

Holding a badge? Check what it points at.