[{"data":1,"prerenderedAt":468},["ShallowReactive",2],{"navigation_docs":3,"-guides-add-a-readme-badge":119,"-guides-add-a-readme-badge-surround":463},[4,23,90,104],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started",[9,13,18],{"title":10,"path":6,"stem":11,"icon":12},"Getting started","1.getting-started\u002Findex","i-lucide-rocket",{"title":14,"path":15,"stem":16,"icon":17},"Try the demo","\u002Fgetting-started\u002Ftry-the-demo","1.getting-started\u002F1.try-the-demo","i-lucide-monitor-play",{"title":19,"path":20,"stem":21,"icon":22},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-play",{"title":24,"path":25,"stem":26,"children":27},"Guides","\u002Fguides","2.guides",[28,31,37,42,47,53,58,63,68,74,79,85],{"title":24,"path":25,"stem":29,"icon":30},"2.guides\u002Findex","i-lucide-map",{"title":32,"path":33,"stem":34,"icon":35,"group":36},"Connect a GitHub repository","\u002Fguides\u002Fconnect-a-github-repository","2.guides\u002F01.connect-a-github-repository","i-lucide-git-branch","Connect a project",{"title":38,"path":39,"stem":40,"icon":41,"group":36},"Analyze a project without GitHub","\u002Fguides\u002Fanalyze-a-project-without-github","2.guides\u002F02.analyze-a-project-without-github","i-lucide-upload",{"title":43,"path":44,"stem":45,"icon":46,"group":36},"Exclude dependency scopes","\u002Fguides\u002Fexclude-dependency-scopes","2.guides\u002F04.exclude-dependency-scopes","i-lucide-filter",{"title":48,"path":49,"stem":50,"icon":51,"group":52},"Scan from GitHub Actions","\u002Fguides\u002Fscan-from-github-actions","2.guides\u002F05.scan-from-github-actions","i-lucide-workflow","Automate",{"title":54,"path":55,"stem":56,"icon":57,"group":52},"Scan from another CI","\u002Fguides\u002Fscan-from-another-ci","2.guides\u002F06.scan-from-another-ci","i-lucide-square-terminal",{"title":59,"path":60,"stem":61,"icon":62,"group":52},"Manage API keys","\u002Fguides\u002Fmanage-api-keys","2.guides\u002F07.manage-api-keys","i-lucide-key-round",{"title":64,"path":65,"stem":66,"icon":67,"group":52},"Create many projects at once","\u002Fguides\u002Fcreate-many-projects-at-once","2.guides\u002F08.create-many-projects-at-once","i-lucide-layers",{"title":69,"path":70,"stem":71,"icon":72,"group":73},"Export reports and SBOMs","\u002Fguides\u002Fexport-reports-and-sboms","2.guides\u002F11.export-reports-and-sboms","i-lucide-download","Act on the results",{"title":75,"path":76,"stem":77,"icon":78,"group":73},"Add a README badge","\u002Fguides\u002Fadd-a-readme-badge","2.guides\u002F12.add-a-readme-badge","i-lucide-badge-check",{"title":80,"path":81,"stem":82,"icon":83,"group":84},"Organizations and plans","\u002Fguides\u002Forganizations-and-plans","2.guides\u002F13.organizations-and-plans","i-lucide-building-2","Organization and team",{"title":86,"path":87,"stem":88,"icon":89,"group":84},"Invite your team","\u002Fguides\u002Finvite-your-team","2.guides\u002F14.invite-your-team","i-lucide-users",{"title":91,"path":92,"stem":93,"children":94},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[95,99],{"title":96,"path":92,"stem":97,"icon":98},"Core concepts","3.core-concepts\u002Findex","i-lucide-lightbulb",{"title":100,"path":101,"stem":102,"icon":103},"The health score","\u002Fcore-concepts\u002Fhealth-score","3.core-concepts\u002F1.health-score","i-lucide-gauge",{"title":105,"path":106,"stem":107,"children":108},"Reference","\u002Freference","5.reference",[109,112],{"title":105,"path":106,"stem":110,"icon":111},"5.reference\u002Findex","i-lucide-book-marked",{"title":113,"path":114,"stem":115,"children":116,"icon":118},"Supported ecosystems","\u002Freference\u002Fecosystems","5.reference\u002F1.ecosystems\u002Findex",[117],{"title":113,"path":114,"stem":115,"icon":118},"i-lucide-package",{"id":120,"title":75,"body":121,"description":456,"extension":457,"links":458,"meta":459,"navigation":460,"path":76,"seo":461,"stem":77,"__hash__":462},"docs\u002F2.guides\u002F12.add-a-readme-badge.md",{"type":122,"value":123,"toc":448},"minimark",[124,129,133,136,141,165,173,176,179,196,199,219,225,229,232,341,344,351,366,369,373,379,396,403,407,414,417,420,424,444],[125,126],"docs-badge",{"badge":127,"project":128},"overall","04be620e-5395-46dc-9bc8-d14b57b46b76",[130,131,132],"p",{},"A badge is a small image in your README that reports one signal from your latest analysis, such as the number of vulnerabilities, the health score, or how many direct dependencies are up to date.\nYou paste one line, once. The image is\nbuilt each time a reader loads it, so it always shows your most recent analysis.",[130,134,135],{},"Badges work on public repositories only. Everything below assumes one.",[137,138,140],"h2",{"id":139},"copy-the-snippet-from-the-integrations-tab","Copy the snippet from the Integrations tab",[130,142,143,144,148,149,152,153,156,157,160,161,164],{},"Open the project, then the ",[145,146,147],"strong",{},"Integrations"," tab. The ",[145,150,151],{},"Quality Badges"," card\nholds the five badges, a preview of the one you picked, and the snippet to\npaste, in ",[145,154,155],{},"Markdown"," and in ",[145,158,159],{},"HTML",". Beside\nthem, ",[145,162,163],{},"Current Metrics"," shows the value behind all five.",[166,167],"u-color-mode-image",{"alt":168,"className":169,"dark":171,"light":172},"Quality Badges card of the Integrations tab, with the five badge buttons, the preview and the Markdown snippet",[170],"wide-capture","\u002Fimages\u002Fdocs\u002Fguides\u002Fadd-a-readme-badge-1-badge-card-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Fadd-a-readme-badge-1-badge-card-light.webp",[130,174,175],{},"Pick a badge, copy the Markdown, paste it at the top of your README. That is the\nwhole task.",[130,177,178],{},"The snippet is an image inside a link:",[180,181,186],"pre",{"className":182,"code":183,"language":184,"meta":185,"style":185},"language-markdown shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","[![Dependency Health](https:\u002F\u002Fimg.shields.io\u002Fendpoint?url=https%3A%2F%2Fapi.deptools.io%2Fbadges%2F\u003Cproject-uuid>%2Foverall)](https:\u002F\u002Fdeptools.io\u002Fdashboard\u002F\u003Cproject-uuid>)\n","markdown","",[187,188,189],"code",{"__ignoreMap":185},[190,191,194],"span",{"class":192,"line":193},"line",1,[190,195,183],{},[130,197,198],{},"It holds two addresses, one inside the other:",[200,201,202,209],"ul",{},[203,204,205,208],"li",{},[187,206,207],{},"https:\u002F\u002Fapi.deptools.io\u002Fbadges\u002F\u003Cproject-uuid>\u002F\u003Cbadge-id>"," is the Deptools\nendpoint. It answers with the current values, in the JSON format shields.io\nexpects. Opening it in a browser is the fastest way to check a badge before\nyou commit it.",[203,210,211,214,215,218],{},[187,212,213],{},"https:\u002F\u002Fimg.shields.io\u002Fendpoint?url=..."," is the image. shields.io calls the\nendpoint above, URL encoded in the ",[187,216,217],{},"url"," parameter, and draws the badge.",[130,220,221,222,224],{},"The ",[145,223,147],{}," tab is closed to viewers, and to anyone who is not a member\nof the organization. The badge itself needs no account, so a viewer who has the\nproject UUID can still assemble the two addresses by hand.",[137,226,228],{"id":227},"the-five-badges","The five badges",[130,230,231],{},"The five below are live. They read the public Deptools demo project, so their\nvalues change every time it is scanned. Each one links to that project's\ndashboard.",[233,234,235,251],"table",{},[236,237,238],"thead",{},[239,240,241,245,248],"tr",{},[242,243,244],"th",{},"Badge",[242,246,247],{},"The badge reads",[242,249,250],{},"Color",[252,253,254,275,295,310,326],"tbody",{},[239,255,256,262,272],{},[257,258,259],"td",{},[125,260],{"badge":261,"project":128},"vulnerabilities",[257,263,264,267,268,271],{},[187,265,266],{},"dependency vulnerabilities",", then the number found by the analysis across the whole graph, ",[145,269,270],{},"direct and transitive",", counted once per affected package",[257,273,274],{},"Green at 0, yellow below 5, red at 5 and above",[239,276,277,282,292],{},[257,278,279],{},[125,280],{"badge":281,"project":128},"commercial",[257,283,284,287,288,291],{},[187,285,286],{},"commercial use",", then ",[187,289,290],{},"safe",", or the number of strong copyleft licenses found",[257,293,294],{},"Green when none was found, red otherwise",[239,296,297,302,307],{},[257,298,299],{},[125,300],{"badge":301,"project":128},"dependencies",[257,303,304,306],{},[187,305,301],{},", then the direct count and the transitive count",[257,308,309],{},"Always blue. It reports a size, not a risk",[239,311,312,317,323],{},[257,313,314],{},[125,315],{"badge":316,"project":128},"uptodate",[257,318,319,322],{},[187,320,321],{},"direct deps up-to-date",", then the share of direct dependencies on their latest version",[257,324,325],{},"Green from 75%, yellow from 50%, orange from 25%, red below 25%",[239,327,328,332,338],{},[257,329,330],{},[125,331],{"badge":127,"project":128},[257,333,334,337],{},[187,335,336],{},"dependency health",", then the overall score out of 10",[257,339,340],{},"Green from 8, yellow from 6, red below 6",[130,342,343],{},"Every badge carries the Deptools logo on the left, in the flat shields.io style.\nThe label, the color and the style all come from the endpoint, so the same badge\nlooks the same everywhere it is embedded.",[130,345,346,347,350],{},"All five read the most recent completed analysis of the project.\nThey always use the most recent completed analysis. Opening an older analysis from ",[145,348,349],{},"Scan History"," does not change the badge.\nA project that has never been scanned,\nor whose scans have all failed, has no completed analysis to read, and all five\nbadges stay grey until one lands.",[130,352,353,354,357,358,361,362,365],{},"Two of them can read ",[187,355,356],{},"unavailable"," on a project that is otherwise fine.\n",[145,359,360],{},"Dependency Health"," and ",[145,363,364],{},"Up-to-date"," both need a value the analysis may not\nhave produced: a project where nothing measurable was found has no overall score\nand no up to date share, and the badge says so rather than printing a zero.",[130,367,368],{},"A badge id the endpoint does not know produces that same grey badge, not an\nerror. So a typo in a manually written URL looks exactly like a project with nothing\nto report.",[137,370,372],{"id":371},"public-repositories-only","Public repositories only",[130,374,375,376,378],{},"A badge is served to anyone who loads it, with no account and no key. So the\nendpoint serves badges for public repositories and refuses everything else, with the\ngrey ",[187,377,356],{}," badge. Two cases:",[200,380,381,390],{},[203,382,383,386,387,389],{},[145,384,385],{},"A private repository."," The card on the ",[145,388,147],{}," tab shows no picker\nand nothing to copy.",[203,391,392,395],{},[145,393,394],{},"A CI upload project."," Is always private, so it never gets a badge.",[130,397,398,399,402],{},"The badge and the dashboard follow the same rule, so a badge someone can load\nis a dashboard they can open.\n",[400,401,32],"a",{"href":33}," covers what\nrepository visibility decides.",[137,404,406],{"id":405},"where-the-badge-links-and-when-it-updates","Where the badge links, and when it updates",[130,408,409,410,413],{},"The image is wrapped in a link to the Deptools dashboard of that project,\n",[187,411,412],{},"https:\u002F\u002Fdeptools.io\u002Fdashboard\u002F\u003Cproject-uuid>",", not to GitHub. The repository is\npublic, so anyone who clicks the badge opens that dashboard with no account: the\nsix dimension scores, the packages that pull the score down, and the graph.",[130,415,416],{},"The snippet never changes. Once it is committed, a new scan is enough to move\nthe numbers, and nothing has to be copied again.",[130,418,419],{},"Two caches sit between an analysis and what a reader sees. Deptools answers with\na one hour cache header, and the site rendering your README caches the image on\nits own side. So a badge can lag a scan by an hour or more. Open the endpoint\ndirectly to see the current values.",[137,421,423],{"id":422},"next-steps","Next steps",[200,425,426,431,436],{},[203,427,428,430],{},[400,429,69],{"href":70}," when you need a\nfile to send rather than a signal to display.",[203,432,433,435],{},[400,434,48],{"href":49}," so the badge\nfollows every push.",[203,437,438,440,441,443],{},[400,439,100],{"href":101}," for what ",[145,442,360],{},"\nmeasures.",[445,446,447],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":185,"searchDepth":449,"depth":449,"links":450},2,[451,452,453,454,455],{"id":139,"depth":449,"text":140},{"id":227,"depth":449,"text":228},{"id":371,"depth":449,"text":372},{"id":405,"depth":449,"text":406},{"id":422,"depth":449,"text":423},"Put a live Deptools badge in your README, choose which of the five it shows, and know when it updates.","md",null,{},{"icon":78,"group":73},{"title":75,"description":456},"QibYcNdvcI7KRvIRreGTAgbws2okP7zLtZ2hCG5bUXI",[464,466],{"title":69,"path":70,"stem":71,"description":465,"icon":72,"group":73,"children":-1},"Produce a CSV audit report, a CycloneDX or SPDX SBOM, and graph exports.",{"title":80,"path":81,"stem":82,"description":467,"icon":83,"group":84,"children":-1},"Understand where your projects live, why the plan belongs to the organization, and how private slots are bought and freed.",1788219402188]