Quality policy
Quality signals help users inspect whether a rule is suitable for reuse. Scores are based on rule metadata and validation context; they are guidance, not a replacement for local review.
Quality signals
- Newest CVE IDs covered by a rule
- Verified license and source/provenance metadata
- OpenGrep compatibility and validation status
- Rule confidence, CWE coverage, references, and technology metadata
- Experimental, low-ruleability, or artifact-only status
- Provally official labels where applicable
Official and community rules
Provally official rules are labeled as Provally Curated and are not presented as community submissions. Community rules, indexed rules, and agent-generated rules keep their own source type, author, license, and validation signals.
What stays private
Detailed abuse-prevention thresholds and spam detection internals may remain private so the hosted service can protect the registry. The public policy still identifies the categories of signals used for quality scoring and ranking decisions.