Public policy

Data and evidence policy

Where catalog data comes from, what each status proves, and what the Registry explicitly does not know.

Effective: 2026-09-04 · Browse Beta

Current data sources

The initial broad catalog comes from a public CC0-1.0 snapshot of awesome-dsh-plugin. Source URLs, snapshot identity, collection time, and content digests are retained. The Registry may also read public npm and GitHub metadata. Publisher supplements are labeled as publisher content and never presented as Registry conclusions.

Four information authorities

  • Imported or publisher content: untrusted text used only to understand a candidate.
  • Registry observation: facts visible from public sources at a recorded time.
  • TestRun: proves only the outcome for the exact artifact, DSH version, Profile, system, and time shown.
  • Control metadata: version, freshness, withdrawal, and lineage.

Evidence limits and freshness

“Listed” does not mean compatible, safe, or functionally verified. Passing one stage does not pass later stages. Sources change, so snapshot and evidence times matter. Stale, withdrawn, unresolved, and untested facts remain visible and are never treated as “no risk.”

Ranking, commercial relationships, and first-party content

Current discovery ranking uses text relevance and bounded public signals. Sponsorship, payment, or maintenance by the Registry team must not change compatibility, security, TestRun outcomes, or evidence levels. Any future paid placement must be labeled and separated from organic results.