This script periodically crawls all Apache project and podling websites to check them for a few specific links or text blocks that all projects are expected to have. The checks include verifying that all required links appear on a project homepage, along with an "image" check if project logo files are in apache.org/img
The script also checks for 3rd party resource references that might be in conflict with our privacy policy.
The Content-Security-Policy (Csp) check is a work in progress: it only checks that the default settings have not been over-ridden. It does not check if the host exceptions have been approved.
View the crawler code, website display code, validation checks details, and raw JSON data.
Last crawl time: Fri, 31 Oct 2025 22:12:26 GMT over 30 websites.
| Check Type | Check Results | Check Description | 
|---|---|---|
| Uri | https://toree.incubator.apache.org | |
| Disclaimer | Apache Toree is an effort undergoing Incubation at The Apache Software Foundation (ASF), sponsored by the Incubator. Incubation is required of all newly accepted projects until a further review indicates that the infrastructure, communications, and decision making process have stabilized in a manner consistent with other successful ASF projects. While incubation status is not necessarily a reflection of the completeness or stability of the code, it does indicate that the project has yet to be fully endorsed by the ASF. Copyright © 2015-2025 The Apache Software Foundation. Licensed under the Apache License, Version 2.0. Apache, the Apache Feather logo, and the Apache Incubator project logo are trademarks of The Apache Software Foundation. | |
| Foundation | The Apache Software Foundation | |
| Events | URL expected to match regular expression: ^https?://((www\.)?apache\.org/events/current-event|events\.apache\.org|www\.apachecon\.com/event-images/snippet\.js)Projects SHOULD include a link to any current CommunityOverCode event, or to the events.apache.org site, as provided by VP, Conferences. | |
| License | URL expected to match regular expression: ^https?://.*apache.org/licenses/?$There should be a "License" (*not* "Licenses") navigation link which points to: http[s]://www.apache.org/licenses[/]. (Do not link to sub-pages) | |
| Thanks | http://www.apache.org/foundation/thanks.html | |
| Security | URL expected to match regular expression: ^(https?://.*apache.org|[^:]*)/.*[Ss]ecurity"Security" should link to either to a project-specific page [...], or to the main http://www.apache.org/security/ page. | |
| Sponsorship | http://www.apache.org/foundation/sponsorship | |
| Trademarks | Apache, the Apache Feather logo, and the Apache Incubator project logo are trademarks of The Apache Software Foundation. | |
| Copyright | Copyright © 2015-2025 The Apache Software Foundation. | |
| Privacy | https://toree.incubator.apache.org/privacy-policy | URL expected to match regular expression: \Ahttps://privacy\.apache\.org/policies/privacy-policy-public\.html\z
                          |
                          \Ahttps?://(?:www\.)?apache\.org/foundation/policies/privacy\.html\z
                          All websites must link to the Privacy Policy. | 
| Resources | Found 5 external resources: {"WARN Mixed Content: The page at 'https://toree.incubator.apache.org/' was loaded over HTTPS, but requested an insecure element 'http://blog.ibmjstart.net/wp-content/uploads/2016/07/vis-comparision1.png'. This request was automatically upgraded to HTTPS, For more information see https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html"=>2, "ERROR Refused to load the image 'https://blog.ibmjstart.net/wp-content/uploads/2016/07/vis-comparision1.png' because it violates the following Content Security Policy directive: \"default-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval' https://www.apachecon.com/ https://www.communityovercode.org/ https://*.apache.org/ https://apache.org/ https://*.scarf.sh/\". Note that 'img-src' was not explicitly set, so 'default-src' is used as a fallback."=>1, ""=>1, "ERROR Refused to load the stylesheet 'https://fonts.googleapis.com/css?family=Patua+One' because it violates the following Content Security Policy directive: \"style-src 'self' data: blob: 'unsafe-inline' 'unsafe-eval' https://www.apachecon.com/ https://www.communityovercode.org/ https://*.apache.org/ https://apache.org/ https://*.scarf.sh/\". Note that 'style-src-elem' was not explicitly set, so 'style-src' is used as a fallback."=>1} | Text of a link expected to match regular expression: Found \d+ external resourcesWebsites must not link to externally hosted resources | 
| Image | toree.svg | |
| Csp_check | OK |