FTI Methodology

How the ForgeOS Trust Index measures package trustworthiness across eight evidence-based dimensions.

How Scoring Works

The ForgeOS Trust Index (FTI) is a composite score (0–100) computed across eight dimensions. Each dimension is weighted by its impact on production reliability and security risk. Scores are recomputed daily as new signals arrive from ecosystems, CVE databases, and community activity feeds.

The algorithm applies a temporal decay function — older signals contribute less than recent ones. A package that patched a CVE six months ago is rewarded less than one that patched it last week. This prevents stale “hall of fame” effects from distorting the index.

The Eight Dimensions

Loading methodology from API…

Temporal Decay

FTI uses an exponential decay function to weight recent evidence more heavily than older signals. A vulnerability patched last week contributes more to your score than one patched 18 months ago.

The decay curve ensures that packages are evaluated on their current trajectory, not historical achievements. A package that neglected security in the past but has been clean since can fully recover as older signals decay out of the window.

Trajectory Classes

Trajectory describes the direction and velocity of a package's score change over the last 90 days. It is independent of the absolute score — a highly-trusted package can have a declining trajectory if recent signals are negative.

Loading methodology from API…

Public Methodology API

The methodology endpoint is publicly available and free. It returns live dimension weights, descriptions, and trajectory class definitions as JSON — useful for building integrations or validating scoring data programmatically.

GET https://forgeos-api.synctek.io/v1/methodology
View standalone API pricing →

Dispute Process

Package maintainers who believe a score is incorrect may submit a dispute. Disputes are reviewed by the FTI team within 10 business days. We only accept disputes backed by evidence (links to commits, CVE patches, test coverage reports).

Common valid dispute reasons: a CVE was patched but our pipeline didn't pick it up yet; test coverage data is stale; a deprecated signal is inflating a dimension.

Submit a dispute via email →