Local or forked packages — npm audit and cargo audit can't see their own upstream history, so provenance and refresh dates are tracked here by hand.
Advisories against anything in the shipped dependency tree — npm (npm audit) and the Rust/wasm subtree actually compiled into tari_l1_wasm (cargo audit, scoped via cargo tree -p tari_l1_wasm).
| Package | Advisory | Severity | Status | Notes |
|---|---|---|---|---|
| loading… | ||||
Each run of the audit process below, kept so a gap in cadence is visible at a glance.
What generates the rows above — rerun on a cadence (monthly, or before any release) and log the result.
| Ecosystem | Command | Scope |
|---|---|---|
| npm | npm audit --json | All resolved packages, direct + transitive. |
| cargo | cargo audit --json (RustSec DB) | Run from the vendored tari_l1_wasm build checkout; cross-referenced against cargo tree -p tari_l1_wasm so only what's actually compiled into the shipped wasm counts. |