Can we add a description of values and their definitions for security criteria items so that it is better understood what each mean. For example, I found the following for npm.md unclear:
- Strong authentication: Partial - what does it mean?
- Update notifications - Partials - means what exactly? Is it just the single maintainer who published but not all others who are listed as maintainers or the team that manages it?
- Package Manager Does Not Run Code - Optional - If it is optional, how does this score? is it a +1 for flagging as passing the criteria or not?