dux_fortinet.fortisase_beta
The FortiSASE Ansible Collection.
Health score
77 / 100
Healthy, with room to improve.
- Excellent
- Good (this collection)
- Fair
- Poor
- Not scored
Observed 6 of 8 signal groups.
Four are needed before a score is published.
4 needed
Category subscores
- Security
- 0%
- Trust
- 100%
- Quality
- 75%
- Maintenance
- 81%
- ansible-core compatibility
- 100%
| Signal | Verdict | What we found | Points | Proved by |
|---|---|---|---|---|
| Signals we could observe | ||||
| security.dependency_boundedness | Not met | 0 of 1 dependencies bounded | 0 / 1 | Published artifact |
| trust.link_claims | Passed | 4 of 4 link URLs declared | 1 / 1 | Published artifact |
| quality.docs | Partly met | readme, 0 doc files | 1.5 / 3 | Published artifact |
| quality.changelog | Passed | changelog.yaml, 1 fragment | 2 / 2 | Published artifact |
| quality.license_quality | Passed | SPDX id declared (GPL-3.0-or-later) | 1 / 1 | Published artifact |
| maintenance.release_recency | Partly met | last release 317 days ago | 2.55 / 3 | Galaxy index |
| maintenance.changelog_recency | Partly met | 1 unreleased changelog fragment | 0.7 / 1 | Published artifact |
| compat.requires_ansible | Passed | >=2.17.0 | 3 / 3 | Published artifact |
| Signals we could not observeNot observed — these are left out of the score rather than counted against it. | ||||
| trust.ansible_membership | Not observed | not shipped in the ansible package | excluded from this score | ansible-build-data |
| quality.tests | Not observed | no test evidence in the published artifact | excluded from this score | Published artifact |
| quality.ci | Not observed | no CI evidence in the published artifact | excluded from this score | Published artifact |
| compat.membership_currency | Not observed | not shipped in the ansible package | excluded from this score | ansible-build-data |
No repository evidence yet. ansible.care has not read any collection's Git repository, so every signal above was proved from a published artifact or from Ansible’s own build data. Tests and CI in particular can be proved present this way but never proved absent — so when we cannot see them, we leave them out of the score rather than counting them against you.
What is costing points
Each of these is a signal we observed and could not fully credit.
- quality.docs
Ship your README and your `docs/` directory INSIDE the published tarball, not only in your Git repository — we do not read repositories at all yet, so a file that exists only there is a file we cannot see. If your `build_ignore` excludes `docs/`, that exclusion is why we observed nothing. Beyond the README this rule counts documentation FILES, so splitting a long README into per-module and per-role pages is what moves it; adding filler pages to raise a count would satisfy the arithmetic and help nobody.
- security.dependency_boundedness
Give every collection dependency you declare in `galaxy.yml` an upper or pinned bound — `<`, `<=`, `==` or `~=` — so that installing your collection cannot silently pull in an arbitrary future release of somebody else’s. If your collection declares no dependencies at all this rule already awards full marks and there is nothing here to change. If we reported a dependency we could not read, the fix is the syntax of its version range rather than the dependency itself.
- maintenance.release_recency
Cut a release to Galaxy. This is the heaviest single rule in the rubric because a release is the one unambiguous, publisher-controlled act of maintenance we can observe without reading your repository — which is also its limitation, and worth saying plainly: a collection under active development that rarely releases is under-credited here, and that is a gap in what we can see rather than a judgement about the work. If your collection is finished rather than abandoned, there is nothing here you should change on our account.
- maintenance.changelog_recency
Write a fragment into `changelogs/fragments/` as each change lands, rather than composing release notes at release time. This reads the same published file as the Quality changelog rule, so shipping and maintaining a changelog answers both at once — if a page told you twice to ship a changelog it would be describing one missing file as two problems. One thing this rule does NOT ask for: an empty fragments directory is not the goal, and cutting a release clears your fragments by design. A maintained changelog with nothing pending still earns partial credit here, so releasing your work does not cost you this rule.
Links
Authors
- Xinwei Du (@dux-fortinet)