External NPM Supply-Chain Audit Index

External NPM Supply-Chain Audit Index

Generated: 2026-05-23

Parent: #1443

This directory tracks external npm package audit evidence for the current dependency-audit wave:

  • #1444: root runtime dependencies
  • #1445: optional native and peer dependencies
  • #1446: root dev-tooling dependencies
  • #1447: shipped nested npm manifests
  • #1448: reusable template, commands, and upstream issue draft
PackageVersionTrackingNative/Binary/Lifecycle SurfaceStatusReport
`@modelcontextprotocol/sdk``1.24.3`#1444, #1447nocompletereport
`chalk``4.1.2`#1444nocompletereport
`chokidar``3.6.0`#1444nocompletereport
`commander``12.1.0`#1444, #1447nocompletereport
`glob``13.0.1`#1444nocompletereport
`graceful-fs``4.2.11`#1444nocompletereport
`js-yaml``4.1.1`#1444, #1447nocompletereport
`listr2``8.3.3`#1444nocompletereport
`ora``5.4.1`#1444nocompletereport
`yaml``2.8.2`#1444nocompletereport
`zod``3.25.76`#1444nocompletereport
`@hono/node-server``1.19.14`#1445nocompletereport
`hnswlib-node``3.0.0`#1445yescompletereport
`hono``4.12.18`#1445nocompletereport
`node-pty``1.1.0`#1445yescompletereport
`ws``8.20.0`#1445nocompletereport
`@xenova/transformers``2.17.2`#1445yescompletereport
`better-sqlite3``12.8.0`#1445yescompletereport
`@matric/eval-client``0.1.0`#1447nocompletereport
`tsx``4.21.0`#1446, #1447yescompletereport
`typescript``5.9.3`#1446, #1447nocompletereport
`@types/js-yaml``4.0.9`#1446, #1447nocompletereport
`@types/node``22.19.2`#1446, #1447nocompletereport
`@types/semver``7.7.1`#1446nocompletereport
`@vitest/coverage-v8``2.1.9`#1446nocompletereport
`@vitest/ui``2.1.9`#1446nocompletereport
`@xterm/headless``6.0.0`#1446nocompletereport
`cli-table3``0.6.5`#1446nocompletereport
`graphology``0.26.0`#1446nocompletereport
`graphology-operators``1.6.1`#1446nocompletereport
`graphology-shortest-path``2.1.0`#1446nocompletereport
`graphology-traversal``0.3.1`#1446nocompletereport
`graphology-types``0.24.8`#1446nocompletereport
`simple-statistics``7.8.8`#1446nocompletereport
`vitest``2.1.9`#1446nocompletereport

Evidence Utilities

Shared Verification

  • Lockfile and manifest evidence came from `package.json`, `package-lock.json`, `agentic/code/addons/droid-bridge/package-lock.json`, and `tools/eval/package-lock.json`.
  • Registry evidence came from `npm view <pkg>@<version> ... --json` on 2026-05-23.
  • Commands in _commands.md avoid running untrusted lifecycle scripts during metadata inspection.
  • Provenance expectation: every report records manifest usage context, lockfile version, repository URL, audited ref or `gitHead` where exposed, lifecycle/native behavior, dependency-source findings, registry signature evidence, findings, clean checks, and follow-up routing.