Last reviewed: 2026-07-25
Compliance score
Learn what CodeCleared’s advisor-driven compliance score represents and how score changes are delivered.
Purpose
The compliance score summarizes Dependency Advisor policy signals for an organization or repository context.
Who
Policy owners and stakeholders tracking changes over time.
Prerequisites
Configure relevant policies and run scans that provide advisor input.
How it works
Review the score with its contributing advisor context; subscribe to score-change webhooks when your process needs automation.
Business rules
The score is advisor-driven and is not a certification, attestation, or guarantee. A score change can emit compliance_score.changed.
Scenarios & edge cases
Score changes unexpectedly: compare policy, commit, and dependency context. No webhook: confirm the endpoint event selection and plan entitlement.
Limits
A score cannot replace human review or a formal compliance assessment.
Common errors
- Advertising the score as certified compliance or a formal attestation.
- Using the official Public trust badge wording is allowed; it is still not a certification.
- Comparing scores without their policy context.