BLOCKED
4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.
- Strong copyleft (GPL-family) licenses in production dependencies
- Network copyleft (AGPL-family) licenses in production dependencies
- Credentials in the current code (2)
The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.
How every claim is graded
Each finding, answer and piece of evidence carries one of these states. The readiness above can never be more certain than the weakest state it rests on.
- Verified
- Observed and independently checked
- Observed
- Read directly from the repository or a named source
- Derived
- Computed deterministically from observed facts
- Company-asserted
- Stated by the company; not proof
- Inferred
- Heuristic reading; raises questions, never blocks
- Conflicting
- Sources disagree
- Unknown
- No evidence either way
- Project license
- LicenseRef-Proprietary · known Observed
- Distribution model
- on_prem Company-asserted
- Dependency licenses
- Known 10 · likely 0 · unknown 6
blocking LIC-010 Strong copyleft (GPL-family) licenses in production dependencies
Observed1 production dependency is under a strong copyleft license: gpl-helpers@0.4.0 (GPL-3.0-or-later). Declared distribution model: on_prem. Counsel should review.
Evidence (2)
- Observed
package-lock.json — gpl-helpers: GPL-3.0-or-later · lockfile.license · licenses.metadata@1 - Observed
package-lock.json — gpl-helpers@0.4.0 · lockfile.entry · dependencies.parse@1
Fingerprint fp_34cf22e8bc122451 · rule v1
blocking LIC-010 Network copyleft (AGPL-family) licenses in production dependencies
Observed1 production dependency is under a network copyleft license: pdf-render-kit@2.1.0 (AGPL-3.0-only). Network copyleft can require source disclosure to users who interact with the software over a network. Declared distribution model: on_prem. Counsel should review before close.
Evidence (2)
- Observed
package-lock.json — pdf-render-kit: AGPL-3.0-only · lockfile.license · licenses.metadata@1 - Observed
package-lock.json — pdf-render-kit@2.1.0 · lockfile.entry · dependencies.parse@1
Fingerprint fp_fce4b3f03ecfbedd · rule v1
blocking SEC-001 Credentials in the current code
ObservedStripe live key in config/.env.production line 1. The value is not reproduced here; fingerprint 792000dea84a3de5.
Evidence (1)
- Observed
config/.env.production:1 — Stripe live key: sk_l… (31 chars) · secret.match · secrets.stripe-live-key@1
Fingerprint fp_7bf5684e91e2c46e · rule v1
blocking SEC-001 Credentials in the current code
ObservedAWS access key ID in src/config.ts line 3. The value is not reproduced here; fingerprint fe916f86aa5d5cca.
Evidence (1)
- Observed
src/config.ts:3 — AWS access key ID: AKIA… (20 chars) · secret.match · secrets.aws-access-key@1
Fingerprint fp_e83b0a535b53e98c · rule v1
material LIC-012 Source-available or restrictive licenses in production dependencies
Observed1 production dependency is under source-available or use-restricted licenses: graph-weaver@1.3.2 (BUSL-1.1).
Evidence (2)
- Observed
package-lock.json — graph-weaver: BUSL-1.1 · lockfile.license · licenses.metadata@1 - Observed
package-lock.json — graph-weaver@1.3.2 · lockfile.entry · dependencies.parse@1
Fingerprint fp_214aca74a57ed063 · rule v1
material LIC-013 Production dependencies with unknown licenses
Derived4 of 13 production dependencies have no license information in the analysed sources (e.g. numpy, scikit-learn, loadash, vendor/tinycrypt). Registry lookup was not enabled.
Evidence (4)
- Observed
ml/requirements.txt — scikit-learn@* · manifest.entry · dependencies.parse@1 - Observed
vendor/tinycrypt · vendored.package · dependencies.vendored@1 - Observed
package-lock.json — loadash@1.0.0 · lockfile.entry · dependencies.parse@1 - Observed
ml/requirements.txt — numpy@>=1.26 · manifest.entry · dependencies.parse@1
Fingerprint fp_52840562c0b3a4d9 · rule v1
material OWN-011 Vendored code without a license file
ObservedVendored code at vendor/tinycrypt (1 file) has no license file or license metadata.
Evidence (1)
- Observed
vendor/tinycrypt · vendored.no_license · licenses.vendored@1
Fingerprint fp_1b011aee5339e804 · rule v1
material REP-001 Dependencies declared without a lockfile
Observedml/requirements.txt declares 3 PyPI dependencies but no lockfile was found, so the exact versions installed are not recorded.
Evidence (1)
- Observed
ml/requirements.txt · manifest.no_lockfile · reproducibility.lockfile@1
Fingerprint fp_5654644c46289aa6 · rule v1 · PyPI:ml/requirements.txt
material REP-002 Manifest and lockfile disagree
Observedpackage-lock.json does not match package.json: 1 declared dependency is missing from the lockfile (zod).
Evidence (1)
- Observed
package-lock.json — zod · lockfile.drift · reproducibility.drift@1
Fingerprint fp_06d9df0faaec4243 · rule v1 · npm:meridian-platform
material REP-004 Container base images not pinned
ObservedDockerfile builds from node:latest, which changes whenever the publisher pushes.
Evidence (1)
- Observed
Dockerfile:1 — node:latest · container.base_image · reproducibility.docker@1
Fingerprint fp_88f9ec93f685af6b · rule v1
material REP-008 Executable binaries committed
Observed1 executable, library, bytecode or archive file(s) are committed (e.g. bin/legacy-export.exe). Their contents and origin cannot be established from the repository.
Evidence (1)
- Observed
bin/legacy-export.exe — executable · file.binary · inventory.binary@1
Fingerprint fp_f342a06d1f7bfe4b · rule v1
material SEC-001 Credentials in the current code
InferredDatabase URL with password in config/.env.production line 2. The value is not reproduced here; fingerprint 76e6e0674be3dec6.
Evidence (1)
- Inferred
config/.env.production:2 — Database URL with password: Pr0d… (13 chars) · secret.match · secrets.database-url@1
Fingerprint fp_70d6a433b2f745ae · rule v1
material SEC-002 Credentials in git history
ObservedGitHub token existed in an earlier version of scripts/deploy.sh and is no longer in the current code. It remains retrievable from history; confirm it was rotated. Fingerprint 1a1d9910c24f9461.
Evidence (1)
- Observed
scripts/deploy.sh — GitHub token: ghp_… (40 chars) · secret.history_match · secrets.github-token@1
Fingerprint fp_a7b365ab1b120a82 · rule v1
material SEC-003 Environment files committed
ObservedEnvironment file config/.env.production is committed.
Evidence (1)
- Observed
config/.env.production · file.env · secrets.env_file@1
Fingerprint fp_17c7fe8a363a1614 · rule v1
material SEC-020 CI workflow runs untrusted pull request code with privileges
Observed.github/workflows/ci.yml is triggered by pull_request_target and checks out pull request code, which then runs with repository secrets and a write token.
Evidence (1)
- Observed
.github/workflows/ci.yml:12 — pull_request_target + checkout of PR head · ci.pr_target_checkout · ci.github_actions@1
Fingerprint fp_07ce8a28034ed08f · rule v1
material SEC-021 CI script injection from untrusted input
Observed.github/workflows/ci.yml interpolates github.event.pull_request.title into a shell command; an attacker who controls that text can run commands in the pipeline.
Evidence (1)
- Observed
.github/workflows/ci.yml:16 — ${{ github.event.pull_request.title }} · ci.script_injection · ci.github_actions@1
Fingerprint fp_f961f0e04a7182e1 · rule v1
material SEC-031 Dependencies fetched over plain HTTP
Observed1 dependency is fetched over plain HTTP (meridian-auth).
Evidence (1)
- Observed
package-lock.json — meridian-auth@0.9.4 · lockfile.entry · dependencies.parse@1
Fingerprint fp_78492bcdb01ea061 · rule v1
material SEC-033 Possible dependency confusion
Inferred1 unscoped package(s) resolve from a private registry (meridian-auth). If the same names are claimed on the public registry, a misconfigured install can fetch the public package instead.
Evidence (1)
- Observed
package-lock.json — meridian-auth@0.9.4 · lockfile.entry · dependencies.parse@1
Fingerprint fp_19cf85222bcfbde1 · rule v1
material SEC-033 Possible dependency confusion
Observedml/requirements.txt adds a private index with --extra-index-url. pip considers every index and installs the highest version, so a public package with the same name as a private one can be installed instead.
Evidence (1)
- Observed
ml/requirements.txt — --extra-index-url https://pypi.meridian.internal/simple · config.extra_index_url · supplychain.extra_index@1
Fingerprint fp_dcfba87d00eeeb25 · rule v1
material SEC-034 Dependency names resembling popular packages
Inferred1 direct dependency has a name one character away from a popular package (loadash). Confirm they are the intended packages.
Evidence (1)
- Observed
package-lock.json — loadash@1.0.0 · lockfile.entry · dependencies.parse@1
Fingerprint fp_9f36f7280727811f · rule v1
minor REP-004 Container base images not pinned
ObservedDockerfile builds from python:3.12-slim, pinned by tag but not by digest.
Evidence (1)
- Observed
Dockerfile:5 — python:3.12-slim · container.base_image · reproducibility.docker@1
Fingerprint fp_78d21b97267087c1 · rule v1
minor REP-006 Toolchain versions not pinned
ObservedToolchain versions are not pinned for: Python (no .python-version or requires-python).
Evidence (0)
No item-level evidence: this finding is derived from counts or configuration described in its summary.
Fingerprint fp_1bb866e7d816d9ad · rule v1
minor REP-007 Build outputs committed to the repository
ObservedBuild output directories are committed: dist. Committed artifacts may not correspond to the committed source.
Evidence (1)
- Observed
dist · repo.build_output · inventory.build_output@1
Fingerprint fp_c8eeabe6abdf320f · rule v1
minor SEC-022 Third-party CI actions not pinned to a commit
Observed1 third-party action reference(s) are pinned to a tag or branch rather than a commit SHA (some-org/deploy-action@v2).
Evidence (1)
- Observed
.github/workflows/ci.yml:13 — some-org/deploy-action@v2 · ci.unpinned_action · ci.github_actions@1
Fingerprint fp_d8daffb1bdf1155b · rule v1
minor SEC-023 Pipelines pipe remote scripts to a shell
Observed1 pipeline or container file(s) pipe a downloaded script into a shell (.github/workflows/ci.yml).
Evidence (1)
- Observed
.github/workflows/ci.yml:17 — curl -sL https://get.example-cdn.io/setup.sh | bash · ci.pipe_to_shell · ci.pipe_to_shell@1
Fingerprint fp_13a446ca9cf1aa3c · rule v1
minor SEC-024 CI token granted write-all permissions
Observed.github/workflows/ci.yml grants the workflow token write-all permissions.
Evidence (0)
No item-level evidence: this finding is derived from counts or configuration described in its summary.
Fingerprint fp_0d06f7a88cd76b4a · rule v1
minor SEC-030 Production dependencies run install scripts
Observed1 production dependency runs install scripts (bcrypt@5.1.1).
Evidence (1)
- Observed
package-lock.json — bcrypt@5.1.1 · lockfile.entry · dependencies.parse@1
Fingerprint fp_6e7faed0bb6fb3dd · rule v1
All dependencies (16)
| Package | Version | Scope | License | Certainty | Component |
|---|
| meridian-features · private | 0.3.1 | production | — | UNKNOWN | PyPI:ml/requirements.txt |
| numpy | >=1.26 | production | — | UNKNOWN | PyPI:ml/requirements.txt |
| scikit-learn | * | production | — | UNKNOWN | PyPI:ml/requirements.txt |
| bcrypt | 5.1.1 | production | MIT | KNOWN | npm:meridian-platform |
| express | 4.18.2 | production | MIT | KNOWN | npm:meridian-platform |
| gpl-helpers | 0.4.0 | production | GPL-3.0-or-later | KNOWN | npm:meridian-platform |
| graph-weaver | 1.3.2 | production | BUSL-1.1 | KNOWN | npm:meridian-platform |
| loadash | 1.0.0 | production | — | UNKNOWN | npm:meridian-platform |
| lodash | 4.17.20 | production | MIT | KNOWN | npm:meridian-platform |
| meridian-auth · private | 0.9.4 | production | — | UNKNOWN | npm:meridian-platform |
| openai | 4.52.7 | production | Apache-2.0 | KNOWN | npm:meridian-platform |
| pdf-render-kit | 2.1.0 | production | AGPL-3.0-only | KNOWN | npm:meridian-platform |
| readable-stream | 2.3.8 | production | MIT | KNOWN | npm:meridian-platform |
| typescript | 5.4.5 | development | Apache-2.0 | KNOWN | npm:meridian-platform |
| third_party/fastjson | — | unknown | MIT | KNOWN | vendored |
| vendor/tinycrypt | — | unknown | — | UNKNOWN | vendored |