On pub.dev, what do a Dart package's pub points and a verified-publisher badge each tell you, and what does neither guarantee?
answer
- quality checks versus identity
- conventions, docs, platforms, analysis, dependencies
- CHANGELOG and example/ count
- a DNS domain, verified once
- neither is a code review
basics
~20 sPub points are pub.dev's automated quality score: file conventions, documentation and an example, platform support, clean static analysis and up-to-date dependencies. A verified-publisher badge proves the publisher controlled a DNS domain. Neither audits the code's correctness, security or maintenance.
solid answer
~40 sPub points come from pub.dev's automated analysis of a published version, in categories dart.dev lists as following Dart file conventions (pubspec, README, CHANGELOG), providing documentation (API doc comments and an illustrative example), supporting multiple platforms, passing static analysis, and supporting up-to-date dependencies. A `colour_tools` author earns them with a well-formed `CHANGELOG.md`, an `example/` program, `///` doc comments, zero analyzer issues and constraints that admit the latest SDK and dependencies. A verified publisher is an identity signal: its creator proved admin access to a DNS domain through Google Search Console, and pub.dev shows that domain instead of a personal email. The domain is checked once, when the publisher is created. Neither signal reviews behaviour: a high score and a badge don't make a package correct, secure or maintained.
code
dart · 18 lines/// A colour in the sRGB space with 8-bit channels.
final class Rgb {
/// Creates a colour from [red], [green] and [blue] channels in 0..255.
const Rgb(this.red, this.green, this.blue);
/// The red channel, 0..255.
final int red;
/// The green channel, 0..255.
final int green;
/// The blue channel, 0..255.
final int blue;
/// Returns the colour as a `#rrggbb` string.
String toHex() =>
'#${[red, green, blue].map((c) => c.toRadixString(16).padLeft(2, '0')).join()}';
}go deeper
Recall that pub points are an automated quality score and that a verified publisher is a domain-backed identity shown with a badge.
Explain which concrete package traits earn points - CHANGELOG, example/, doc comments, clean analysis, current constraints - and how publisher verification and transfer work.
Use both as a first filter when adopting a dependency, then check what neither covers: activity, issue response, licence, tests and discontinued status.
Decide what your organisation publishes under a verified publisher and what signals it requires before adopting third-party packages.
## Two different signals A package page on pub.dev carries several signals that are easy to blur together. Two of them are set by the publishing process itself: | Signal | What it measures | Who produces it | |---|---|---| | **Pub points** | objective, automatable quality traits of the published version | pub.dev's automated analysis | | **Verified publisher** badge | that the publisher's creator controlled a DNS domain | a one-time domain verification | | Likes | how many signed-in developers liked the package | the community | Pub points answer "does this package follow the ecosystem's conventions?"; the badge answers "who stands behind it?". Neither answers "is this code any good?". ## How pub points are earned When pub points were introduced, dart.dev described them as awarding points (rather than subtracting for issues) across categories of measurable quality: - **Follow Dart file conventions** - a valid `pubspec.yaml`, a `README.md`, and a `CHANGELOG.md` whose headings carry version numbers. - **Provide documentation** - API documentation from `///` doc comments on the public API, and an **illustrative example**, conventionally a program under `example/`. - **Support multiple platforms** - supporting as many Dart and Flutter platforms as possible; the detected set can be declared explicitly with the `platforms` key in `pubspec.yaml`. - **Pass static analysis** - code free of errors, warnings and lints. - **Support up-to-date dependencies** - constraints that admit the latest Dart and Flutter SDKs and the latest versions of dependencies. For a colour-utilities package this translates into a short checklist: keep the changelog current, ship a runnable example, document every public class and function, keep `dart analyze` clean, and widen constraints when dependencies release new majors. `dart create -t package` already scaffolds `CHANGELOG.md`, `README.md` and an `example/` file, though not a `LICENSE`. Prereleases such as `2.0.0-dev.1` do not affect the package's analysis score, do not appear in search results, and do not replace the stable version's README and documentation. ## How a verified publisher works A **verified publisher** is a pub.dev identity tied to a domain: 1. Sign in to pub.dev with a Google Account and choose **Create Publisher**. 2. Enter the domain, such as `example.com`. 3. Complete the verification flow in Google Search Console, which checks that you administer that domain property (DNS records may take hours to show up). Consequences worth knowing: - pub.dev shows the publisher domain and contact address instead of the uploader's personal email, plus a badge in search results and on package pages. - Domain ownership is checked **only once**, at creation. Losing the domain later does not cost the owner the publisher, and buying the domain grants the new owner nothing. - `dart pub publish` cannot put a brand-new package directly under a publisher. Publish the first version from a Google Account, then transfer it on the package's **Admin** tab - you must be an uploader and a publisher admin. The transfer **cannot be reversed**. - Every member of a publisher may upload new versions, which removes the single-uploader bottleneck of a personally owned package. ## What neither guarantees - **Correctness** - the analysis checks conventions and lints, not whether conversions or contrast calculations are right. - **Security** - no human review of the code is implied by either signal. - **Maintenance** - a package can score well and still have no releases or issue responses for years. - **Current domain control** - the badge records a verification that happened once. ## Using them when choosing a dependency Treat both as a first filter. Low points usually mean missing documentation, analyzer issues or stale constraints - worth knowing before you adopt. A verified publisher tells you whom to hold accountable. Then do the part no score does: read the repository activity, the changelog, open issues, test coverage, the licence, and whether the package is marked **DISCONTINUED**. ## Summary - Pub points: automated, convention-level quality of a version. - Verified publisher: a domain-backed identity checked once. - Neither is a review of behaviour, security or upkeep.
- Why can't `dart pub publish` put a brand-new package straight under a verified publisher?The pub client doesn't support publishing a new package directly to a publisher. You publish the first version from a Google Account, then someone who is both an uploader and a publisher admin transfers it on the package's Admin tab. The transfer can't be reversed, and afterwards every publisher member can upload.
- A package has high pub points but no release in two years. What does that tell you?Only that the analysed version met pub.dev's automated checks. Points don't measure issue response, release cadence or whether the code still works with your stack. Check the repository activity, the changelog, open issues and whether the package is marked discontinued before depending on it.
A verified-publisher badge is like a registered business name on a shop sign: it tells you who runs the shop, not whether the food is good. Pub points are the hygiene inspection of the kitchen layout, not a tasting.
saying these in an interview costs you the question
- Pub points measure how many projects depend on the package
- A verified-publisher badge means the package's code was reviewed
- An example/ folder and CHANGELOG.md are cosmetic and never affect scoring
- Publishing a fixed prerelease raises the stable version's pub points
- pub.dev re-verifies the publisher's domain before every upload