Skip to content

Questions on Plugins, Scores, and Tolerance #793

Discussion options

You must be logged in to vote

Hi Michael, thanks for reaching out!

I'll answer questions 2 and 3 first, and come back to question 1.

Good Starting Weights for Analyses

For question 2, proper scoring weights for each plugin: the simplest model would be to equally weight all plugins, which would mean putting all analysis entries directly under the analyze block in your policy file. This gives a good starting point from which you can decide if specific analyses are more important to you for your use of open source software.

Note

You can use the hc scoring command to see a representation of how these percentages break down to debug your scoring configuration.

Good Starting Risk Tolerance

We've historically started with 0.5

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@michael-hoover
Comment options

@alilleybrinker
Comment options

Answer selected by alilleybrinker
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants