slsa-framework / slsa

Supply-chain Levels for Software Artifacts
https://slsa.dev
Other
1.48k stars 212 forks source link

Google preferring v0.1 instead of v1.0 #1047

Open MarkLodato opened 2 months ago

MarkLodato commented 2 months ago

Google seems to be preferring v0.1 instead of v1.0 in many cases. For example, the top result for "SLSA requirements" is https://slsa.dev/spec/v0.1/requirements. Note that it does also return links to v1.0. Ideally we could somehow configure it so that only the v1.0 links are returned, unless you specifically search for v0.1. Probably other software projects run into similar issues.

Anyone with experience with this, your input would be valuable!

kpk47 commented 2 months ago

Maybe we update our robots.txt to prevent indexing anything other than the latest official release? It would be equally bad for the top result to be the draft of v1.1.

haydentherapper commented 1 month ago

A related search engine issue: Google appears to be parsing time_verified on the VSA spec and setting the article date to 1985:

image