PageSourceSearch

https://community.finos.org/assets/js/f50729b3.37685e7b.js

js finos.org collected 2026-09-24 08:59:29 UTC 21,820 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkfinos_community=self.webpackChunkfinos_community||[]).push([[1309],{5800:(e,t,i)=>{i.r(t),i.d(t,{assets:()=>l,contentTitle:()=>o,default:()=>h,frontMatter:()=>c,metadata:()=>n,toc:()=>d});const n=JSON.parse('{"id":"development-infrastructure/code-validation/intro","title":"Code Validation","description":"Code validation in FINOS CI: static analysis, coverage, and supply-chain checks that keep security and quality high across GitHub-based repositories.","source":"@site/../docs/development-infrastructure/code-validation/intro.md","sourceDirName":"development-infrastructure/code-validation","slug":"/development-infrastructure/code-validation/intro","permalink":"/docs/development-infrastructure/code-validation/intro","draft":false,"unlisted":false,"editUrl":"https://github.com/finos/community/edit/main/website/../docs/development-infrastructure/code-validation/intro.md","tags":[],"version":"current","frontMatter":{"id":"intro","title":"Code Validation","description":"Code validation in FINOS CI: static analysis, coverage, and supply-chain checks that keep security and quality high across GitHub-based repositories."},"sidebar":"mainSidebar","previous":{"title":"Continuous Delivery","permalink":"/docs/development-infrastructure/continuous-delivery"},"next":{"title":"Code Climate","permalink":"/docs/development-infrastructure/code-validation/codeclimate"}}');var s=i(4848),r=i(8453);const c={id:"intro",title:"Code Validation",description:"Code validation in FINOS CI: static analysis, coverage, and supply-chain checks that keep security and quality high across GitHub-based repositories."},o=void 0,l={},d=[{value:"Security vulnerabilities responsible disclosure",id:"security-vulnerabilities-responsible-disclosure",level:2},{value:"Matrix of validation features and supported languages",id:"matrix-of-validation-features-and-supported-languages",level:2},{value:"Continuous validation",id:"continuous-validation",level:2},{value:"CLA",id:"cla",level:3},{value:"Project compliance scan",id:"project-compliance-scan",level:3},{value:"Ignoring validations",id:"ignoring-validations",level:4},{value:"Exporting to CSV",id:"exporting-to-csv",level:4}];function a(e){const t={a:"a",code:"code",h2:"h2",h3:"h3",h4:"h4",li:"li",p:"p",pre:"pre",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.p,{children:"In order to assess Security, Quality and Legal compliance of software hosted by the Foundation, project leads and committers can configure integrations with third-party systems that are provided by the Foundation; the result of these processes can be published in the project's documentation to improve the final consumer experience and when requesting activation."}),"\n",(0,s.jsx)(t.p,{children:"Below is the list of code validation systems currently available, across supported languages and validation features."}),"\n",(0,s.jsx)(t.h2,{id:"security-vulnerabilities-responsible-disclosure",children:"Security vulnerabilities responsible disclosure"}),"\n",(0,s.jsxs)(t.p,{children:["Read the ",(0,s.jsx)(t.a,{href:"/docs/governance/Software-Projects/cve-responsible-disclosure",children:"FINOS security vulnerabilities responsible disclosure"})," document to know how security incidents are managed across FINOS projects. Use ",(0,s.jsx)(t.a,{href:"/docs/development-infrastructure/code-validation/whitesource",children:"WhiteSource"})," to configure your FINOS project for automated scanning."]}),"\n",(0,s.jsx)(t.h2,{id:"matrix-of-validation-features-and-supported-languages",children:"Matrix of validation features and supported languages"}),"\n",(0,s.jsxs)(t.table,{children:[(0,s.jsx)(t.thead,{children:(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.th,{children:"Features"}),(0,s.jsx)(t.th,{style:{textAlign:"center"},children:"C#"}),(0,s.jsx)(t.th,{style:{textAlign:"center"},children:"Clojure"}),(0,s.jsx)(t.th,{style:{textAlign:"center"},children:"Java"}),(0,s.jsx)(t.th,{style:{textAlign:"center"},children:"Javascript"}),(0,s.jsx)(t.th,{style:{textAlign:"center"},children:"Python"})]})}),(0,s.jsxs)(t.tbody,{children:[(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:(0,s.jsx)(t.strong,{children:"Legal compliance"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Check libraries for problematic/undefined licenses"}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Generates legal reports"}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:(0,s.jsx)(t.strong,{children:"Security"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Scans code for security vulnerabilities"}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"}),", ",(0,s.jsx)(t.a,{href:"coverityscan",children:"CoverityScan"}),", ",(0,s.jsx)(t.a,{href:"sonarcloud",children:"SonarCloud"})]}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"})}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"}),", ",(0,s.jsx)(t.a,{href:"codeclimate",children:"CodeClimate"}),", ",(0,s.jsx)(t.a,{href:"coverityscan",children:"CoverityScan"}),", ",(0,s.jsx)(t.a,{href:"sonarcloud",children:"SonarCloud"})]}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"}),", ",(0,s.jsx)(t.a,{href:"codeclimate",children:"CodeClimate"}),",",(0,s.jsx)(t.a,{href:"sonarcloud",children:"SonarCloud"})]}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"})})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Check libraries for security vulnerabilities"}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"}),", ",(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})]}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"}),", ",(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})]}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"}),", ",(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})]}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"}),", ",(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})]}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"https://github.com/finos/code-scanning",children:"FINOS Code Scanning"}),", ",(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})]})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:(0,s.jsx)(t.strong,{children:"Quality"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Measures test coverage"}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"sonarcloud",children:"SonarCloud"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"codeclimate",children:"CodeClimate"}),",",(0,s.jsx)(t.a,{href:"sonarcloud",children:"SonarCloud"})]}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"codeclimate",children:"CodeClimate"}),", ",(0,s.jsx)(t.a,{href:"sonarcloud",children:"SonarCloud"})]}),(0,s.jsx)(t.td,{style:{textAlign:"center"}})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Check libraries for bugs"}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Check libraries for outdated versions"}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Check unused libraries"}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Check libraries for release activity"}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"whitesource",children:"WhiteSource"})})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Scans code for hacks and todos"}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Scans code for bad practices"}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"coverityscan",children:"CoverityScan"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsxs)(t.td,{style:{textAlign:"center"},children:[(0,s.jsx)(t.a,{href:"codeclimate",children:"CodeClimate"}),", ",(0,s.jsx)(t.a,{href:"coverityscan",children:"CoverityScan"})]}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"codeclimate",children:"CodeClimate"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"}})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"Scans code for bugs"}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"coverityscan",children:"CoverityScan"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"},children:(0,s.jsx)(t.a,{href:"coverityscan",children:"CoverityScan"})}),(0,s.jsx)(t.td,{style:{textAlign:"center"}}),(0,s.jsx)(t.td,{style:{textAlign:"center"}})]})]})]}),"\n",(0,s.jsx)(t.h2,{id:"continuous-validation",children:"Continuous validation"}),"\n",(0,s.jsx)(t.p,{children:"FINOS provides a set of tools, specifically GitHub Apps and Actions, that enforce a continuous scanning across the FINOS GitHub repositories."}),"\n",(0,s.jsx)(t.h3,{id:"cla",children:"CLA"}),"\n",(0,s.jsxs)(t.p,{children:["To help project leads validate external 
1contributor's identity and capacity to contribute code to the Foundation please visit ",(0,s.jsx)(t.a,{href:"https://community.finos.org/docs/governance/Software-Projects/EasyCLA/",children:"https://community.finos.org/docs/governance/Software-Projects/EasyCLA/"})," to know more about FINOS CLAs."]}),"\n",(0,s.jsx)(t.h3,{id:"project-compliance-scan",children:"Project compliance scan"}),"\n",(0,s.jsx)(t.p,{children:"FINOS have developed a tool that scans all the GitHub repositories across all FINOS orgs and generates a report based on the following quality and compliance validations:"}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"has-admin"})," - One or more admin collaborators were found in this GitHub repository. FINOS Governance doesn't allow GitHub users to have Admin rights on repositories, therefore it must be removed."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"has-user"})," - One or more user collaborators were found in this GitHub repository. FINOS Governance only allows GitHub users to be added via Teams. Please remove it, therefore it must be removed."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"disabled-issues"})," - This GitHub repository does not have GitHub Issues enabled; make sure that there is a documented way to submit questions, feature requests and other communications to the project team."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-teams"})," - This GitHub repository does not grant permissions to any FINOS Team, although it should be configured to grant access to project maintainers defined as ",(0,s.jsx)(t.a,{href:"https://github.com/orgs/finos/teams",children:"GitHub Teams"}),". Please email ",(0,s.jsx)(t.a,{href:"mailto:[email protected]",children:"[email protected]"})," and coordinate changes to the repository access permissions."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-issue-templates"})," - This GitHub repository does not use issue templates; please check the ",(0,s.jsx)(t.a,{href:"https://github.com/finos/software-project-blueprint/tree/master/.github/ISSUE_TEMPLATE",children:"issue template blueprints"}),"."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-contributing"})," - ",(0,s.jsx)(t.code,{children:"CONTRIBUTING.md"})," file is missing; check the ",(0,s.jsx)(t.a,{href:"https://github.com/finos/software-project-blueprint/blob/master/CONTRIBUTING.md",children:"CONTRIBUTING.md template"}),"."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-code-conduct"})," - ",(0,s.jsx)(t.code,{children:"CODE_OF_CONDUCT.md"})," file is missing; check the ",(0,s.jsx)(t.a,{href:"https://github.com/finos/software-project-blueprint/blob/master/.github/CODE_OF_CONDUCT.md",children:"CODE_OF_CONDUCT.md template"}),"."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"notice-nok"})," - ",(0,s.jsx)(t.code,{children:"NOTICE"})," file is incomplete; check line 4 of the ",(0,s.jsx)(t.a,{href:"https://github.com/finos/software-project-blueprint/blob/master/NOTICE",children:"NOTICE template"}),"."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-notice"})," - ",(0,s.jsx)(t.code,{children:"NOTICE"})," file is missing; check the ",(0,s.jsx)(t.a,{href:"https://github.com/finos/software-project-blueprint/blob/master/NOTICE",children:"NOTICE template"}),"."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-readme"})," - ",(0,s.jsx)(t.code,{children:"README.md"})," file is missing; check the ",(0,s.jsx)(t.a,{href:"https://github.com/finos/software-project-blueprint/blob/master/README.template.md",children:"README.md template"}),"."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-description"})," - This GitHub repository does not have a general description defined; the ",(0,s.jsx)(t.code,{children:"Edit"})," button is seen when on the repositories main page, which is the ",(0,s.jsx)(t.code,{children:"Code"})," tab."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"is-archivable"})," - This repository belongs to project ",(0,s.jsx)(t.code,{children:"{{project-name}}"})," which is archived, therefore the GitHub repository is expected to be ar
1chived too. @finos-staff will get in touch with the project lead to sort it out."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"readme-nok"})," - ",(0,s.jsx)(t.code,{children:"README.md"})," file is incomplete; check the ",(0,s.jsx)(t.a,{href:"https://github.com/finos/software-project-blueprint/blob/master/README.template.md",children:"README.md template"})," and make sure that ",(0,s.jsx)(t.code,{children:"## Contributing"})," and ",(0,s.jsx)(t.code,{children:"## License"})," sections exist."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-badge"})," - ",(0,s.jsx)(t.code,{children:"README.md"})," file is missing the FINOS badge; check the ",(0,s.jsx)(t.a,{href:"https://github.com/finos/software-project-blueprint/blob/master/README.template.md",children:"README.md template"})," and make sure that it embeds one of SVG FINOS badges."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"wrong-badge"})," - Our internal records state that this project is in ",(0,s.jsx)(t.code,{children:"{{project-state}}"})," state, whereas ",(0,s.jsx)(t.code,{children:"README.md"})," states ",(0,s.jsx)(t.code,{children:"{{readme-state}}"}),"; make sure that ",(0,s.jsx)(t.code,{children:"README.md"})," embeds the right FINOS badge."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"repo-not-on-file"})," - We don't have this repository on file. We will fix this issue on our side as soon as possible and keep you posted."]}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.code,{children:"no-whitesource"})," - WhiteSource configuration was not found; make sure that dependencies are scanned against security vulnerabilities. Read more on ",(0,s.jsx)(t.a,{href:"/docs/development-infrastructure/code-validation/whitesource",children:"the WhiteSource page"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(t.p,{children:["Code is publicly available on ",(0,s.jsx)(t.a,{href:"https://github.com/finos/metadata-tool",children:"https://github.com/finos/metadata-tool"}),", the command to invoke is ",(0,s.jsx)(t.code,{children:"check-project-repos"}),"."]}),"\n",(0,s.jsx)(t.h4,{id:"ignoring-validations",children:"Ignoring validations"}),"\n",(0,s.jsxs)(t.p,{children:["There may be corner cases, for example repositories that contain data don't need whitesource integration. In those cases, it is possible to define a ",(0,s.jsx)(t.code,{children:".finos-blueprint.json"})," file in the root folder, with the following structure:"]}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{children:'{\n  "ignore" : [\n    "no-whitesource",\n    "readme-nok"\n  ]\n}\n'})}),"\n",(0,s.jsx)(t.h4,{id:"exporting-to-csv",children:"Exporting to CSV"}),"\n",(0,s.jsx)(t.p,{children:"Here's a useful command to transform the metadata-tool JSON output in CSV."}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{children:'cat finos-repo-validation.json| jq -r \'.[] | [.org, .["repo-name"], .validations["has-admin"], .validations["has-user"], .validations["no-teams"], .validations["no-issues"], .validations["no-issue-templates"], .validations["no-contributing"], .validations["no-code-conduct"], .validations["notice-nok"], .validations["no-notice"], .validations["no-readme"], .validations["no-description"], .validations["is-archivable"], .validations["readme-nok"], .validations["no-badge"], .validations["wrong-badge"], .validations["repo-not-on-file"], .validations["no-whitesource"]] | @csv\'\n'})})]})}function h(e={}){const{wrapper:t}={...(0,r.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(a,{...e})}):a(e)}},8453:(e,t,i)=>{i.d(t,{R:()=>c,x:()=>o});var n=i(6540);const s={},r=n.createContext(s);function c(e){const t=n.useContext(r);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:c(e.components),n.createElement(r.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.