Goal
Audit the production dependency and static-resource surface without opportunistic upgrades.
Acceptance criteria
- Inventory each vendored production dependency.
- Verify required version, license, provenance, approved files, and runtime hashes.
- Preserve secure-metadata v0.1.0 bytes and provenance.
- Confirm same-origin loading with no runtime CDN, npm, or GitHub artifact fetch.
- Add tests only for concrete coverage gaps.
Goal
Audit the production dependency and static-resource surface without opportunistic upgrades.
Acceptance criteria