Universe Supply Chain

tari-l1-wallet-ui — dependency & advisory tracker
—
Open findings
—
Fixed
—
Vendored packages
—
Days since last scan

Vendored & patched 0

Local or forked packages — npm audit and cargo audit can't see their own upstream history, so provenance and refresh dates are tracked here by hand.

Findings 0

Advisories against anything in the shipped dependency tree — npm (npm audit) and the Rust/wasm subtree actually compiled into tari_l1_wasm (cargo audit, scoped via cargo tree -p tari_l1_wasm).

PackageAdvisorySeverityStatusNotes
loading…

Scan log 0

Each run of the audit process below, kept so a gap in cadence is visible at a glance.

Audit process

What generates the rows above — rerun on a cadence (monthly, or before any release) and log the result.

EcosystemCommandScope
npmnpm audit --jsonAll resolved packages, direct + transitive.
cargocargo audit --json (RustSec DB)Run from the vendored tari_l1_wasm build checkout; cross-referenced against cargo tree -p tari_l1_wasm so only what's actually compiled into the shipped wasm counts.