code-assurance-initiative/CodeAssuranceIndex
87.9
Strong · 3 October 2026
20.2k
lines of production code
C#
primary language
8
measurements over time
What this system is
The Code Assurance Index is a security measurement system that computes, verifies, and publishes standardized scores for codebases using deterministic scoring rubrics and signed delivery packages. It provides a public-facing web application that aggregates corpus-wide security data, including noise measurements and compliance marks, while maintaining a registry to manage publication grants and immutable historical trends. The platform supports both programmatic access via a CLI and web APIs, ensuring reproducible results through strict versioning, cryptographic signing, and rigorous performance and visual regression testing.
Features
CAI web host introduces partner-key access control, granular rate limiting, and public badge endpoints
The web application now enforces optional partner-only API access via the ApiAccess guard (configurable with Api:RequirePartnerKey), classifies traffic into distinct rate-limit buckets (Trusted, Principal, RegistryPublic, Crowd, Badge, etc.) with specific per-IP or per-principal budgets to prevent abuse of public probes and crowd endpoints, and exposes a new /api/badge/{provider}/{owner}/{repo}.svg endpoint that renders a standardized, reproducible CAI badge by fetching evidence from configured issuers and folding it through the standard's scorer.
src/Cai.Web · high confidence
Corpus manifest is now cryptographically signed at deploy time
A new shell script, tools/sign-corpus.sh, has been added to sign the noise corpus manifest (noise-corpus-1.0.json) during deployment. This script generates a signing key if one does not exist, signs the manifest using SHA-256, and writes the corresponding public key to the source tree based on the manifest's keyId. The signature is verified immediately after creation to ensure integrity, ensuring that the corpus manifest has not been tampered with since the deploy that produced it.
tools · high confidence
Introduce CAI reference CLI for scoring and signed delivery
The \cai\ command-line tool is now available to compute, verify, and sign Code Assurance Index (CAI) scores. Users can run \cai score\ to generate a CAI headline from an evidence bundle, or \cai verify\ to reproduce and validate a published score against its rubric. The CLI also supports a delivery workflow: \cai keygen\ generates Ed25519 keys, \cai sign\ creates a signed, shareable delivery package (including a fix for locale-dependent timestamp formatting to ensure valid RFC 3339 output), and \cai verify-delivery\ performs offline trust checks on those packages. Diagnostic logging is structured and directed to stderr to keep stdout clean for machine-readable results.
src/Cai.Cli · high confidence
Introduces domain logic for noise measurement, crowd rating, and compliance marking
This change adds the core domain models and calculation logic for the noise measurement standard within the Cai.Web.Noise project. It defines how findings are classified by specificity (pointwise, structural, statistical, advisory) to ensure comparable noise rates, and implements the computation of micro (pooled) and macro (cluster-weighted) averages to prevent repository domination. It introduces the 'CAI-measured' compliance mark, which is granted mechanically based on four verifiable conditions (run against holdout, deadline, reproducibility, full publication) rather than subjective audit. Additionally, it establishes the crowd-rating infrastructure, including queue management for contested and spot-checked findings, rater stratification to track affiliation and language bias, and the handling of honeypot calibration items.
src/Cai.Web.Noise · high confidence
New corpus-wide and group-level security pages
The application now publishes a comprehensive 'state of the corpus' document at /state-of-the-corpus, which aggregates security measurements across all codebases. This includes a main sheet detailing the population of measured codebases and specific findings (vulnerabilities, disclosure policies, secrets, supply chain controls), with explicit caveats that counts are floors and shares are taken over distinct populations. Additionally, new pages are generated for individual advisories and packages (requiring a minimum of 3 surveys), as well as per-language and per-country breakdowns (requiring minimums of 5 surveys and 10 codebases respectively). These group pages provide median CAI scores and finding shares scoped to their specific subsets, with indexes linking to the detailed views.
src/Cai.Pages · high confidence
New local dev tools for visual regression and accessibility auditing
Added \pixel-contrast.mjs\ and \shoot.mjs\ to the local development UI toolkit to address accessibility and visual verification gaps that automated tools like axe-core cannot fully resolve. \shoot.mjs\ captures screenshots of every published page shape to allow human review of rendering across themes and viewports, while specifically detecting islands that render only headings without content and identifying low-contrast SVG text labels in dark mode. \pixel-contrast.mjs\ performs pixel-level contrast analysis on elements obscured by gradients or translucent headers, providing accurate contrast ratios where axe-core abstains, ensuring that components like the theme toggle meet AA standards.
tools/localdev/ui · high confidence
New local development tools for end-to-end corpus rendering and link validation
Added three new scripts to the local development environment to improve verification of published pages. \check-links.py\ performs a static sweep of all internal links across every published HTML file to detect dangling references, distinguishing between broken links and links to authored pages outside the build scope. \run-corpus-e2e.sh\ orchestrates a full end-to-end test by booting the local imprint editor, CAI host, and site server, seeding a scratch registry with realistic subject data, and using Playwright to screenshot the rendered pages in a browser. \seed-local-registry.py\ generates the fixture data for the E2E script, including specific edge cases like single-reading subjects, rare advisories, and legacy 1.0 schema deliveries to ensure all page variants render correctly.
tools/localdev · high confidence
New site syndication publisher with safe sweep and reconciliation logic
A new syndication subsystem has been added to the registry to automatically publish and reconcile the standard's pages on the target site. This includes an HTTP client for pushing, withdrawing, and listing pages, a background service that runs periodic sweeps, and a reconciliation engine that compares the site's current state against the composed corpus. The publisher implements fail-closed safety measures: it refuses to withdraw pages if doing so would remove more than one-third of the site (preventing accidental mass deletion during schema mismatches or outages), holds back corpus-wide aggregate pages until the granted corpus is sufficiently populated (preventing stale readings during migrations), and reports null listings as 'no change' rather than emptying the site. Operators can monitor the last sweep's status, including any refused withdrawals or held aggregates, via a dedicated memory service.
src/Cai.Web.Registry/Syndication · high confidence
Publication grants and immutable corpus trend lines
The registry now supports publication grants for subjects, allowing an owner organization to grant or withdraw publication status for a specific repository; this state is tracked in a new \publications\ table to maintain an audit trail. Additionally, the system introduces immutable corpus readings (\corpus\_readings\ table) that record the state of the codebase corpus at specific points in time. These readings are append-only and never recomputed, ensuring that the trend line displayed to users is a faithful record of what was published at each moment, preventing silent data loss if publication grants are later withdrawn.
src/Cai.Web.Registry/Infrastructure · high confidence
Behavioural changes
Delivery package format 1.2: rubric integrity, narration, and subject metadata
The delivery package format has advanced to version 1.2, introducing several key capabilities for producers and verifiers. The builder now requires a ResolvedRubric to fold evidence, ensuring the scoring criteria are anchored to a specific published document via a content hash, which prevents rubric substitution. New payload fields allow producers to include optional narration (changelog and system overview) and subject metadata (programming languages and geographic origin), providing richer context for the measured codebase. The issuer identity has moved from cai.canine.dev to codeassuranceindex.info, and the JSON Schema ID has been updated to reflect this domain change. Verification logic has been hardened to strictly require the correct rubric document for reproducibility checks and to treat absent reproduction results as failures rather than successes.
src/Cai.Delivery/Domain · high confidence
Fixes rubric version ordering and introduces coherence and surface-floor scoring rules
The scoring library now correctly resolves the latest rubric version by parsing the \rubric-YYYY.MM.N\ format numerically, preventing stale versions from being served due to flawed string sorting. The scoring fold enforces stricter quality signals: the headline band is capped so it never out-promises the weakest category, and the Architecture lens is dropped or capped when the codebase has insufficient analyzable surface. Additionally, the \RubricCatalogStore\ now validates that published catalogs are attested to their directory names and rejects unparseable version strings to prevent path traversal and unbounded cache growth.
src/Cai.Scoring · high confidence
Migrate nginx vhosts from cai.canine.dev to codeassuranceindex.info
The nginx configuration has been updated to replace the legacy cai.canine.dev domain with the new codeassuranceindex.info domain. This change introduces dedicated vhost files for the API (api.codeassuranceindex.info) and the application (app.codeassuranceindex.info), ensuring that interactive tools like the calculator and verifier are correctly reachable on their own hostnames rather than being blocked by the marketing site. The main apex domain (codeassuranceindex.info) is configured as a split host, routing /api/ and schema endpoints to the Cai.Web backend while serving the imprint marketing site on the root path. The old cai.canine.dev vhost files have been removed.
deploy/nginx · high confidence
Preprod tier isolation and domain migration documentation
The deploy configuration now fully isolates the preprod environment from production by introducing a dedicated systemd service (\cai-web-preprod.service\) on port 8240, a separate database path, and its own trusted signing key set, ensuring that preprod submissions do not affect the live register. A new Python script (\preprod-corpus.py\) transforms the production corpus at build time for preprod by assigning a unique key ID and unblocking embargo dates, allowing rehearsals to test the full workflow without permanent side effects. Additionally, the deployment documentation (\DEPLOY.md\ and \PREPROD.md\) details the migration from \cai.canine.dev\ to the new \codeassuranceindex.info\ domain, explaining the nginx split-host configuration for API and app subdomains and the permanent redirect strategy for legacy URLs.
deploy · high confidence
Registry access control and health reporting enhancements
The registry now enforces strict read-access controls via a new authorization model: consumers can only access deliveries they own or for which an active, non-expired grant exists from the owner, with access evaluated at read time against specific delivery or repository scopes. Additionally, the public health endpoint now reports the status of site publishing sweeps, allowing operators to see if a publisher has recently swept the registry, which aids in diagnosing why certain evidence might not be visible on the standard's pages.
src/Cai.Web.Registry/Endpoints · high confidence
Registry deployment configuration and safe-by-default behavior
The registry service, hosted on api.codeassuranceindex.info within Cai.Web, is now properly configured for production and pre-production environments. Systemd drop-ins ensure the SQLite database and trusted keys persist across deployments by pointing to a stable directory, while bearer token secrets are loaded from a protected environment file. The service is safe-by-default: if unconfigured, it serves a degraded health status, an empty key set, and returns 401 for authenticated requests rather than failing with 500 errors. Additionally, rate limiting is now traffic-class aware, distinguishing between trusted loopback traffic, authenticated principals, public health/keys endpoints, and general public traffic to prevent throttling internal delivery loops.
deploy/registry · high confidence
Repository relocation, structural refactoring, and security hardening
The project has moved to the \code-assurance-initiative\ organization and is now the Code Assurance Index. The codebase has been restructured into distinct projects (\Cai.Web\, \Cai.Web.Registry\, \Cai.Web.Noise\, \Cai.Scoring\, \Cai.Delivery\) to enforce separation of concerns, with the registry and noise standard isolated into their own assemblies. Security has been significantly improved: a private sample key has been removed from the repository, the \DeliverySigner.Sign\ method is no longer public to prevent payload substitution, and the scoring API now requires an explicit rubric version to ensure deterministic, reproducible scores. Additionally, the rubric catalog now pins scoring constants and band cutlines, and the signed delivery package includes survey completeness data.
(repo-wide) · high confidence
Fixes
Sample delivery package now uses a dedicated, non-production key ID
The sample delivery package is now signed with a unique key ID (\cai-ed25519-sample\) instead of the production key ID, ensuring that verification against the live API does not fail due to key mismatches. The tool generates a fresh keypair for each run, keeping the private key out of the repository to prevent accidental leaks, while the public key is included in the example's key set for offline verification. Additionally, the sample's issuer name is updated to reflect the current standard's identity, correcting outdated claims about who stands behind the score.
tools/resign-sample · high confidence
Test coverage
Added BenchmarkDotNet suite for scoring performance tracking; Added visual parity tests for noise mark, rate, and record pages; Added visual regression testing infrastructure and baseline manifest; Expanded test coverage for scoring, authentication, and compliance logic.
Dependencies
Upgrade to .NET 10 and refresh core dependencies
The project has been upgraded to target .NET 10.0 across all components, including the CLI, web host, scoring engine, and test suite. This migration brings in updated versions of key libraries such as xunit v3 for testing, NSec.Cryptography for package signing, and OpenTelemetry instrumentation (v1.16.0) for observability, while also pinning SQLitePCLRaw to version 3.0.3 to ensure compatibility with the newer Microsoft.Data.Sqlite runtime.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 88 → 88 (-0.0)
Lenses
- Code Health 98 → 98 (+0.0)
- Architecture 88 → 88 (+0.0)
- Maturity 90 → 90 (+0.0)
- Readiness 93 → 93 (-0.6)
- Security 99 → 99 (+0.0)
- Accessibility 100 → 100 (+0.0)
- Performance 85 → 85 (+0.0)
New (1)
- Flaky test: Cai.Tests::Cai.Tests.PublishedResultApiTests.Cai.Tests.PublishedResultApiTests.STAR_A_Correction_Is_Visible_AS_A_Correction
API surface
- Unchanged — 51 HTTP endpoints
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
code-assurance-initiative/CodeAssuranceIndex was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 08eeb4332e98927fd8582b799c6da7f8cf873586 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-8fe32cd45d00.