Skip to content

Author verified

An Author verified badge on a listing means that someone who could change the repository asked findsafeskills to list it, and proved it at the time of the check. Authors can claim any listing, including listings we discovered on our own.

What it means, and what it doesn't

It means ownership of the ability to change the repository at the time of the check.

It is not identity, intent or safety: it does not tell you who the person is, what they intend, or that the code is safe. A malicious author can verify their own malicious repository. For that reason the badge is never combined with the safety rating, and the two always appear separately. Read what the safety scan does and doesn't check.

How an author claims a listing

  1. Open the listing. If we found it on our own, it is still yours to claim.
  2. Sign in.
  3. Click Claim this listing. We show the current safety scan result and give you a validation key.
  4. Prove you can change the repository with one of the two proofs below, then check it.

The two proofs

GitHub push access

For authors signed in with GitHub who claim a GitHub listing. We ask GitHub whether your account can push to the repository. There is nothing to edit in the repository.

A validation key in the repository

Add this sentence to the repository's README, or put it alone in a file named .findsafeskills, replacing the placeholder with your key:

Verification that the author submitted this repo to FindSafeSkills and has access to it: <your-validation-key>

The key is not a secret. It is a random value meant to be public, it is unrelated to anything else, and it only works for the listing it was issued for, so copying it into another repository gains nothing. This proof works without a GitHub sign-in and on any code host.

When verification lapses

Verification is tied to the repository itself, not just its name. If the key is removed from the README or file, or the repository is transferred or renamed to another owner, the verification lapses. The new owner does not inherit it. You can verify again at any time by repeating a proof. Verified listings are re-checked regularly.

The safety scan at claim time

When you claim a listing we scan its current manifest and README and show you the result. Verification does not depend on that result. If a finding is a false positive, it can be disputed with the same form as any other listing's finding.