[{"data":1,"prerenderedAt":455},["ShallowReactive",2],{"navigation_docs":3,"-guides-track-scores-over-time":124,"-guides-track-scores-over-time-surround":450},[4,23,95,109],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started",[9,13,18],{"title":10,"path":6,"stem":11,"icon":12},"Getting started","1.getting-started\u002Findex","i-lucide-rocket",{"title":14,"path":15,"stem":16,"icon":17},"Try the demo","\u002Fgetting-started\u002Ftry-the-demo","1.getting-started\u002F1.try-the-demo","i-lucide-monitor-play",{"title":19,"path":20,"stem":21,"icon":22},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-play",{"title":24,"path":25,"stem":26,"children":27},"Guides","\u002Fguides","2.guides",[28,31,37,42,47,53,58,63,68,74,79,84,90],{"title":24,"path":25,"stem":29,"icon":30},"2.guides\u002Findex","i-lucide-map",{"title":32,"path":33,"stem":34,"icon":35,"group":36},"GitHub repository","\u002Fguides\u002Fconnect-a-github-repository","2.guides\u002F01.connect-a-github-repository","i-lucide-git-branch","Connect a project",{"title":38,"path":39,"stem":40,"icon":41,"group":36},"Without GitHub","\u002Fguides\u002Fanalyze-a-project-without-github","2.guides\u002F02.analyze-a-project-without-github","i-lucide-upload",{"title":43,"path":44,"stem":45,"icon":46,"group":36},"Dependency scopes","\u002Fguides\u002Fexclude-dependency-scopes","2.guides\u002F04.exclude-dependency-scopes","i-lucide-filter",{"title":48,"path":49,"stem":50,"icon":51,"group":52},"GitHub Actions","\u002Fguides\u002Fscan-from-github-actions","2.guides\u002F05.scan-from-github-actions","i-lucide-workflow","Automate",{"title":54,"path":55,"stem":56,"icon":57,"group":52},"Another CI","\u002Fguides\u002Fscan-from-another-ci","2.guides\u002F06.scan-from-another-ci","i-lucide-square-terminal",{"title":59,"path":60,"stem":61,"icon":62,"group":52},"Manage API keys","\u002Fguides\u002Fmanage-api-keys","2.guides\u002F07.manage-api-keys","i-lucide-key-round",{"title":64,"path":65,"stem":66,"icon":67,"group":52},"Many projects at once","\u002Fguides\u002Fcreate-many-projects-at-once","2.guides\u002F08.create-many-projects-at-once","i-lucide-layers",{"title":69,"path":70,"stem":71,"icon":72,"group":73},"Scores over time","\u002Fguides\u002Ftrack-scores-over-time","2.guides\u002F10.track-scores-over-time","i-lucide-trending-up","Act on the results",{"title":75,"path":76,"stem":77,"icon":78,"group":73},"Reports and SBOMs","\u002Fguides\u002Fexport-reports-and-sboms","2.guides\u002F11.export-reports-and-sboms","i-lucide-download",{"title":80,"path":81,"stem":82,"icon":83,"group":73},"README badge","\u002Fguides\u002Fadd-a-readme-badge","2.guides\u002F12.add-a-readme-badge","i-lucide-badge-check",{"title":85,"path":86,"stem":87,"icon":88,"group":89},"Organizations and plans","\u002Fguides\u002Forganizations-and-plans","2.guides\u002F13.organizations-and-plans","i-lucide-building-2","Organization and team",{"title":91,"path":92,"stem":93,"icon":94,"group":89},"Invite your team","\u002Fguides\u002Finvite-your-team","2.guides\u002F14.invite-your-team","i-lucide-users",{"title":96,"path":97,"stem":98,"children":99},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[100,104],{"title":101,"path":97,"stem":102,"icon":103},"Core concepts","3.core-concepts\u002Findex","i-lucide-lightbulb",{"title":105,"path":106,"stem":107,"icon":108},"The health score","\u002Fcore-concepts\u002Fhealth-score","3.core-concepts\u002F1.health-score","i-lucide-gauge",{"title":110,"path":111,"stem":112,"children":113},"Reference","\u002Freference","5.reference",[114,117],{"title":110,"path":111,"stem":115,"icon":116},"5.reference\u002Findex","i-lucide-book-marked",{"title":118,"path":119,"stem":120,"children":121,"icon":123},"Ecosystems","\u002Freference\u002Fecosystems","5.reference\u002F1.ecosystems\u002Findex",[122],{"title":118,"path":119,"stem":120,"icon":123},"i-lucide-package",{"id":125,"title":126,"body":127,"description":443,"extension":444,"links":445,"meta":446,"navigation":447,"path":70,"seo":448,"stem":71,"__hash__":449},"docs\u002F2.guides\u002F10.track-scores-over-time.md","Track scores over time",{"type":128,"value":129,"toc":435},"minimark",[130,139,149,152,157,175,183,200,217,236,244,250,292,298,305,318,322,333,336,339,367,371,384,387,395,408,412],[131,132,133,134,138],"p",{},"One analysis says where a project stands today. A series of them says where it\nis going. The ",[135,136,137],"strong",{},"Stats"," tab of a project keeps every completed scan, charts what\nmoved between them, and opens any of them in the dashboard.",[131,140,141,142,145,146,148],{},"Open a project from your organization's project list, or from ",[135,143,144],{},"Project\noverview"," in the dashboard sidebar. The page opens on ",[135,147,137],{},".",[131,150,151],{},"A project on a public GitHub repository has a public project page, exactly like\nits dashboard: anyone with the link can view the history, with no account. A private\nrepository and a CI upload project can be viewed by the organization and by the\nviewers invited on the project.",[153,154,156],"h2",{"id":155},"read-the-scan-history","Read the scan history",[131,158,159,160,163,164,163,167,170,171,174],{},"The period selector at the top of the tab offers ",[135,161,162],{},"Last 7 days",", ",[135,165,166],{},"Last 30 days",[135,168,169],{},"Last 3 months",", and ",[135,172,173],{},"All time",". All charts and the table below follow the selected period.",[176,177],"u-color-mode-image",{"alt":178,"className":179,"dark":181,"light":182},"Stats tab with the period selector on All time, the Overall Health Score chart, the Current Profile radar and the six Dimension Scores sparklines",[180],"wide-capture","\u002Fimages\u002Fdocs\u002Fguides\u002Ftrack-scores-over-time-1-score-chart-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Ftrack-scores-over-time-1-score-chart-light.webp",[131,184,185,186,189,190,193,194,199],{},"The tab charts your scores at two levels. ",[135,187,188],{},"Overall Health Score"," plots the\nproject score of every scan in the period. ",[135,191,192],{},"Dimension Scores"," repeats that for\neach of the six dimensions, as a sparkline with its current value and its delta.\nBoth use the 0 to 10 scale and the color bands of\n",[195,196,198],"a",{"href":197},"\u002Fcore-concepts\u002Fhealth-score#score-labels","the health score",". In either one the line breaks at a scan that\nproduced no score instead of dropping to zero. Nothing was measurable there,\nwhich is not a zero.",[131,201,202,203,205,206,163,209,212,213,216],{},"A pill in the ",[135,204,188],{}," header reads ",[135,207,208],{},"Improving",[135,210,211],{},"Stable"," or\n",[135,214,215],{},"Declining",". It reports the direction of the whole period, not the last\nmovement, and it needs at least three scans with a score before it appears.",[131,218,219,220,223,224,227,228,231,232,235],{},"Four more cards chart the rest of the period: ",[135,221,222],{},"Vulnerabilities"," by severity,\n",[135,225,226],{},"Dependency Growth"," as direct and transitive counts, ",[135,229,230],{},"Outdated %"," for direct\npackages and for all of them, and ",[135,233,234],{},"Avg Outdatedness",", the average time your\npackages are behind their latest release.",[131,237,238,240,241,148],{},[135,239,222],{}," draws one bar per scan, with the four severities stacked\ninside it. The height of a bar is the total for that scan. To follow one\nseverity, read its segment and not the top of the bar. The pills in the card\nheader count the latest scan alone, not the period, and a scan that found nothing\nshows a single pill reading ",[135,242,243],{},"All clear",[176,245],{"alt":246,"className":247,"dark":248,"light":249},"The four trend cards over the period, Vulnerabilities as stacked bars by severity, Dependency Growth, Outdated % and Avg Outdatedness",[180],"\u002Fimages\u002Fdocs\u002Fguides\u002Ftrack-scores-over-time-2-charts-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Ftrack-scores-over-time-2-charts-light.webp",[131,251,252,255,256,163,259,163,262,265,266,269,270,163,273,276,277,280,281,170,284,287,288,291],{},[135,253,254],{},"Scan History",", at the bottom, is the table.\nThere is one row per completed scan, newest first, with five rows per page.\nIt shows ",[135,257,258],{},"Date",[135,260,261],{},"Score",[135,263,264],{},"Deps",", then ",[135,267,268],{},"Critical",",\n",[135,271,272],{},"High",[135,274,275],{},"Moderate"," and ",[135,278,279],{},"Low"," for the vulnerability counts, ",[135,282,283],{},"Strong\nCopyleft",[135,285,286],{},"Outdated",", the share of packages behind their latest release\nwith the average delay beside it. The newest row carries a ",[135,289,290],{},"Latest"," badge, and\na scan with nothing measurable shows two dashes where its score would be.",[176,293],{"alt":294,"className":295,"dark":296,"light":297},"Scan History table, one row per completed scan, with a Dashboard button on each row",[180],"\u002Fimages\u002Fdocs\u002Fguides\u002Ftrack-scores-over-time-3-scan-history-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Ftrack-scores-over-time-3-scan-history-light.webp",[131,299,300,301,304],{},"Every completed scan is in that table, whatever started it: ",[135,302,303],{},"Run scan",", the\nAPI, the GitHub Action, any other pipeline. A scan that fails leaves no row\nbehind.",[131,306,307,308,310,311,314,315,317],{},"Deptools keeps every completed scan for the life of the project, so ",[135,309,173],{},"\nreally is all of them. Deleting the project deletes its analyses with it, and so\ndoes leaving the ",[135,312,313],{},"Pro"," plan for a private project.\n",[195,316,85],{"href":86}," covers what a\ndowngrade removes.",[153,319,321],{"id":320},"open-a-past-analysis","Open a past analysis",[131,323,324,325,328,329,332],{},"The ",[135,326,327],{},"Dashboard"," button at the end of a row opens the dashboard on that\nanalysis. A banner names the date it comes from, and ",[135,330,331],{},"View latest"," goes back to\nthe most recent one.",[131,334,335],{},"The address carries the analysis, so it stays with the analysis when you switch tabs and can be sent to\nsomeone else. Whoever can open the project's dashboard can open it.",[131,337,338],{},"Three things behave differently in that view:",[340,341,342,349,358],"ul",{},[343,344,345,348],"li",{},[135,346,347],{},"The deltas compare that analysis to the one before it",", never to the latest.\nA scan from March reports what changed in March.",[343,350,351,354,355,148],{},[135,352,353],{},"Exports describe the analysis you opened."," The CSV, the SBOM and the graph\nfiles are all built in your browser from what is on screen. See\n",[195,356,357],{"href":76},"Export reports and SBOMs",[343,359,360,363,364,148],{},[135,361,362],{},"The badge does not follow."," It always reads the most recent completed\nanalysis. See ",[195,365,366],{"href":81},"Add a README badge",[153,368,370],{"id":369},"understand-a-score-change","Understand a score change",[131,372,373,374,163,377,163,380,276,382,148],{},"Every score on the dashboard carries its delta against the previous scan, in\npoints out of 10. The sidebar shows one for the project score and one for each of\nthe six dimensions, and the score card at the top of each analysis tab shows the\nsame number again. The project page reports the same movement as a percentage,\nunder ",[135,375,376],{},"Overall Score",[135,378,379],{},"Dependencies",[135,381,222],{},[135,383,286],{},[131,385,386],{},"A delta below 0.05 point is not printed, so a score that looks unchanged has\noften moved a little. And when either of the two scans could not measure a\ndimension, no delta is shown at all rather than one computed against nothing.",[131,388,389,390,394],{},"A delta says how much. It never says why, and the cause is frequently not in your\ncode: a vulnerability was published, days passed, ecosystem data was refreshed,\nor a dependency that could not be resolved last time resolved this time.\n",[195,391,393],{"href":392},"\u002Fcore-concepts\u002Fhealth-score#why-a-score-changes","Why a score changes"," lists\nthem.",[131,396,397,398,401,402,405,406,148],{},"To find what moved, open the two analyses in two browser tabs and compare the\nsame dashboard tab in each. The dimension with the largest delta tells you which\ntab to open first. For a package by package answer, export both analyses and\ncompare the two files. A ",[135,399,400],{},"CSV"," is the readable one, as long as you pick the\nsame scope and the same columns on each side. ",[135,403,404],{},"Graph JSON"," always carries the\nwhole graph, so it is the one to script against. See\n",[195,407,357],{"href":76},[153,409,411],{"id":410},"next-steps","Next steps",[340,413,414,419,425,430],{},[343,415,416,418],{},[195,417,105],{"href":106}," for what the six dimensions\nmeasure and what makes each of them move.",[343,420,421,424],{},[195,422,423],{"href":49},"Scan from GitHub Actions"," so the history\nfills on its own, on every push.",[343,426,427,429],{},[195,428,357],{"href":76}," to turn a scan\ninto a file you can compare or send.",[343,431,432,434],{},[195,433,85],{"href":86}," for the scan\ncooldown and for what each plan allows.",{"title":436,"searchDepth":437,"depth":437,"links":438},"",2,[439,440,441,442],{"id":155,"depth":437,"text":156},{"id":320,"depth":437,"text":321},{"id":369,"depth":437,"text":370},{"id":410,"depth":437,"text":411},"Read the scan history, open a past analysis, and understand why a score moved.","md",null,{},{"title":69,"icon":72,"group":73},{"title":126,"description":443},"WcRUnvPlOa5OQV6ubSoMnda5tOey9RzUtQOwTwV_YDQ",[451,453],{"title":64,"path":65,"stem":66,"description":452,"icon":67,"group":52,"children":-1},"Provision a whole portfolio of CI upload projects in one API request, and get back the name to UUID mapping your pipelines need.",{"title":75,"path":76,"stem":77,"description":454,"icon":78,"group":73,"children":-1},"Produce a CSV audit report, a CycloneDX or SPDX SBOM, and graph exports.",1788560545070]