blocking LIC-010 Strong copyleft (GPL-family) licenses in production dependencies
Observed1 production dependency is under a strong copyleft license: gpl-helpers@0.4.0 (GPL-3.0-or-later). Declared distribution model: on_prem. Counsel should review.
Evidence (2)
- Observed
package-lock.json — gpl-helpers: GPL-3.0-or-later · lockfile.license · licenses.metadata@1 - Observed
package-lock.json — gpl-helpers@0.4.0 · lockfile.entry · dependencies.parse@1
Fingerprint fp_34cf22e8bc122451 · rule v1
blocking LIC-010 Network copyleft (AGPL-family) licenses in production dependencies
Observed1 production dependency is under a network copyleft license: pdf-render-kit@2.1.0 (AGPL-3.0-only). Network copyleft can require source disclosure to users who interact with the software over a network. Declared distribution model: on_prem. Counsel should review before close.
Evidence (2)
- Observed
package-lock.json — pdf-render-kit: AGPL-3.0-only · lockfile.license · licenses.metadata@1 - Observed
package-lock.json — pdf-render-kit@2.1.0 · lockfile.entry · dependencies.parse@1
Fingerprint fp_fce4b3f03ecfbedd · rule v1
blocking SEC-001 Credentials in the current code
ObservedStripe live key in config/.env.production line 1. The value is not reproduced here; fingerprint 792000dea84a3de5.
Evidence (1)
- Observed
config/.env.production:1 — Stripe live key: sk_l… (31 chars) · secret.match · secrets.stripe-live-key@1
Fingerprint fp_7bf5684e91e2c46e · rule v1
blocking SEC-001 Credentials in the current code
ObservedAWS access key ID in src/config.ts line 3. The value is not reproduced here; fingerprint fe916f86aa5d5cca.
Evidence (1)
- Observed
src/config.ts:3 — AWS access key ID: AKIA… (20 chars) · secret.match · secrets.aws-access-key@1
Fingerprint fp_e83b0a535b53e98c · rule v1
material AI-002 Declaration contradicts recorded AI evidence
ConflictingDeclared as written by people (src/billing/**), but 1 matching file(s) carry AI attribution (e.g. src/billing/invoice.ts).
Evidence (2)
- Company-asserted
meridian-systems/meridian-platform:acquicode.yml — src/billing/** → human: Billing rules were written by hand by the core team · declaration.origin · declaration.origin@1 - Observed direct
commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1
Fingerprint fp_235bc8dcb4afa396 · rule v1
material AI-003 Attribution sources disagree
ConflictingAttribution records for src/ai/summarize.ts at 58d65e3e4738 disagree on 10 line(s): one source says AI, another says human.
Evidence (2)
- Observed direct
src/ai/summarize.ts @ 58d65e3e4738 — git-ai authorship/3.0.0 · provenance.git_ai_note · ai.git_ai_note@1 - Company-asserted direct
src/ai/summarize.ts @ 58d65e3e4738 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1
Fingerprint fp_4427a89bf2492389 · rule v1
material AI-005 AI-attributed changes without review evidence
Derived4 of 5 commit(s) carrying AI attribution landed without a pull request or merge (pushed directly to the analysed branch), so there is no record of review.
Evidence (4)
- Observed direct
commit 58d65e3e4738 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1 - Observed direct
commit 5f8ec9d222c4 — aider: · commit.ai_signal · ai.commit_signal@1 - Observed direct
commit 4c9a23cdf304 — Co-authored-by: Cursor Agent <cursoragent@cursor.com> · commit.ai_signal · ai.commit_signal@1 - Observed direct
commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1
Fingerprint fp_0303827158ddeaf2 · rule v1
material AI-008 AI tool terms not declared
ObservedEvidence shows use of aider, cursor, github-copilot but the plan tier, IP indemnity and output-filter settings in force were not declared. Indemnities typically depend on paid commercial tiers and specific settings.
Evidence (0)
No item-level evidence: this finding is derived from counts or configuration described in its summary.
Fingerprint fp_fc8d772c0a87b8b6 · rule v1
material AI-011 Files predominantly attributed to AI with no recorded human authorship
Derived1 file(s) have line-level records attributing at least 80% of their current lines to AI tools and none to a named person (e.g. src/search/index.ts). This is a statement about the records, not a legal conclusion on authorship.
Evidence (2)
- Company-asserted direct
src/search/index.ts @ d0bc1462d623 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1 - Observed direct
commit d0bc1462d623 — Copilot <198982749+Copilot@users.noreply.github.com> · commit.ai_signal · ai.commit_signal@1
Fingerprint fp_7a90a7c416a2bc5a · rule v1
material AI-012 Model weights or binary model artifacts committed
Observed1 model artifact(s) are committed (e.g. models/churn.onnx). Their training data, license and origin cannot be established from the repository.
Evidence (1)
- Observed
models/churn.onnx · file.model_artifact · ai.model_artifact@1
Fingerprint fp_5a168622f9f84716 · rule v1
material AID-001 Product depends on external AI providers
ObservedThe product calls external AI services: OpenAI. All direct provider usage found is with OpenAI; its pricing, terms and model deprecations flow straight into the product.
Evidence (2)
- Observed
src/ai/summarize.ts — api.openai.com · code.ai_endpoint · ai_dependency.endpoint@1 - Observed
package-lock.json — openai@4.52.7 · lockfile.entry · dependencies.parse@1
Fingerprint fp_3c7b083acc6dda3e · rule v1
material EVQ-002 Declarations older than the code they describe
StaleThe origin declaration for src/billing/** is dated 2024-06-30; 1 matching file(s) changed after that date (e.g. src/billing/invoice.ts).
Evidence (1)
- Company-asserted
meridian-systems/meridian-platform:acquicode.yml — src/billing/** → human: Billing rules were written by hand by the core team · declaration.origin · declaration.origin@1
Fingerprint fp_8385f0edbc45e3ed · rule v1
material LIC-012 Source-available or restrictive licenses in production dependencies
Observed1 production dependency is under source-available or use-restricted licenses: graph-weaver@1.3.2 (BUSL-1.1).
Evidence (2)
- Observed
package-lock.json — graph-weaver: BUSL-1.1 · lockfile.license · licenses.metadata@1 - Observed
package-lock.json — graph-weaver@1.3.2 · lockfile.entry · dependencies.parse@1
Fingerprint fp_214aca74a57ed063 · rule v1
material LIC-013 Production dependencies with unknown licenses
Derived4 of 13 production dependencies have no license information in the analysed sources (e.g. numpy, scikit-learn, loadash, vendor/tinycrypt). Registry lookup was not enabled.
Evidence (4)
- Observed
ml/requirements.txt — scikit-learn@* · manifest.entry · dependencies.parse@1 - Observed
vendor/tinycrypt · vendored.package · dependencies.vendored@1 - Observed
package-lock.json — loadash@1.0.0 · lockfile.entry · dependencies.parse@1 - Observed
ml/requirements.txt — numpy@>=1.26 · manifest.entry · dependencies.parse@1
Fingerprint fp_52840562c0b3a4d9 · rule v1
material OWN-001 Contributors without a recorded IP agreement
Company-asserted3 of 5 human contributors (5 commits) have no IP agreement in the supplied register: Chris Dale <chris.dale@gmail.com> (2), Priya Natarajan <priya@quickdev-agency.com> (2), octodev <4412345+octodev@users.noreply.github.com> (1).
Evidence (1)
- Company-asserted
meridian-systems/meridian-platform:acquicode.yml — 3 register entries · declaration.ip_register · ownership.register@1
Fingerprint fp_848bd0d14535075b · rule v1
material OWN-002 Contributions predate the recorded agreement
Company-asserted1 contributor(s) committed before their recorded agreement date: Ben Kaplan (first commit 2023-09-12, signed 2024-06-01). Confirm the agreements assign prior work.
Evidence (1)
- Company-asserted
meridian-systems/meridian-platform:acquicode.yml — 3 register entries · declaration.ip_register · ownership.register@1
Fingerprint fp_a593eae5ced2d520 · rule v1
material OWN-004 Third-party copyright notices in first-party source
Observed1 copyright notice(s) in first-party source name 1 other holder(s) (GeoCorp Ltd). Files: src/lib/geo.ts.
Evidence (1)
- Observed
src/lib/geo.ts:2 — Copyright 2014 GeoCorp Ltd · file.copyright_notice · thirdparty.copyright@1
Fingerprint fp_17fc8a987437918f · rule v1
material OWN-005 Stack Overflow references in source
Observed1 reference(s) to Stack Overflow / Stack Exchange posts in 1 source file(s) (e.g. src/utils/retry.ts). Code copied from those posts is licensed CC BY-SA.
Evidence (1)
- Observed
src/utils/retry.ts:2 — https://stackoverflow.com/questions/38213668/promise-retry-design-patterns · file.stackoverflow_reference · thirdparty.stackoverflow@1
Fingerprint fp_3eed04f51fa86ea1 · rule v1
material OWN-007 File-level license identifiers differing from the project
Observed1 first-party file(s) declare GPL-2.0-only in SPDX headers, differing from the project license (LicenseRef-Proprietary) (e.g. src/lib/parse.ts).
Evidence (1)
- Observed
src/lib/parse.ts:1 — GPL-2.0-only · file.spdx_identifier · licenses.spdx_header@1
Fingerprint fp_2af3ae93590d474a · rule v1
material OWN-011 Vendored code without a license file
ObservedVendored code at vendor/tinycrypt (1 file) has no license file or license metadata.
Evidence (1)
- Observed
vendor/tinycrypt · vendored.no_license · licenses.vendored@1
Fingerprint fp_1b011aee5339e804 · rule v1
material REP-001 Dependencies declared without a lockfile
Observedml/requirements.txt declares 3 PyPI dependencies but no lockfile was found, so the exact versions installed are not recorded.
Evidence (1)
- Observed
ml/requirements.txt · manifest.no_lockfile · reproducibility.lockfile@1
Fingerprint fp_5654644c46289aa6 · rule v1 · PyPI:ml/requirements.txt
material REP-002 Manifest and lockfile disagree
Observedpackage-lock.json does not match package.json: 1 declared dependency is missing from the lockfile (zod).
Evidence (1)
- Observed
package-lock.json — zod · lockfile.drift · reproducibility.drift@1
Fingerprint fp_06d9df0faaec4243 · rule v1 · npm:meridian-platform
material REP-004 Container base images not pinned
ObservedDockerfile builds from node:latest, which changes whenever the publisher pushes.
Evidence (1)
- Observed
Dockerfile:1 — node:latest · container.base_image · reproducibility.docker@1
Fingerprint fp_88f9ec93f685af6b · rule v1
material REP-008 Executable binaries committed
Observed1 executable, library, bytecode or archive file(s) are committed (e.g. bin/legacy-export.exe). Their contents and origin cannot be established from the repository.
Evidence (1)
- Observed
bin/legacy-export.exe — executable · file.binary · inventory.binary@1
Fingerprint fp_f342a06d1f7bfe4b · rule v1
material SEC-001 Credentials in the current code
InferredDatabase URL with password in config/.env.production line 2. The value is not reproduced here; fingerprint 76e6e0674be3dec6.
Evidence (1)
- Inferred
config/.env.production:2 — Database URL with password: Pr0d… (13 chars) · secret.match · secrets.database-url@1
Fingerprint fp_70d6a433b2f745ae · rule v1
material SEC-002 Credentials in git history
ObservedGitHub token existed in an earlier version of scripts/deploy.sh and is no longer in the current code. It remains retrievable from history; confirm it was rotated. Fingerprint 1a1d9910c24f9461.
Evidence (1)
- Observed
scripts/deploy.sh — GitHub token: ghp_… (40 chars) · secret.history_match · secrets.github-token@1
Fingerprint fp_a7b365ab1b120a82 · rule v1
material SEC-003 Environment files committed
ObservedEnvironment file config/.env.production is committed.
Evidence (1)
- Observed
config/.env.production · file.env · secrets.env_file@1
Fingerprint fp_17c7fe8a363a1614 · rule v1
material SEC-020 CI workflow runs untrusted pull request code with privileges
Observed.github/workflows/ci.yml is triggered by pull_request_target and checks out pull request code, which then runs with repository secrets and a write token.
Evidence (1)
- Observed
.github/workflows/ci.yml:12 — pull_request_target + checkout of PR head · ci.pr_target_checkout · ci.github_actions@1
Fingerprint fp_07ce8a28034ed08f · rule v1
material SEC-021 CI script injection from untrusted input
Observed.github/workflows/ci.yml interpolates github.event.pull_request.title into a shell command; an attacker who controls that text can run commands in the pipeline.
Evidence (1)
- Observed
.github/workflows/ci.yml:16 — ${{ github.event.pull_request.title }} · ci.script_injection · ci.github_actions@1
Fingerprint fp_f961f0e04a7182e1 · rule v1
material SEC-031 Dependencies fetched over plain HTTP
Observed1 dependency is fetched over plain HTTP (meridian-auth).
Evidence (1)
- Observed
package-lock.json — meridian-auth@0.9.4 · lockfile.entry · dependencies.parse@1
Fingerprint fp_78492bcdb01ea061 · rule v1
material SEC-033 Possible dependency confusion
Inferred1 unscoped package(s) resolve from a private registry (meridian-auth). If the same names are claimed on the public registry, a misconfigured install can fetch the public package instead.
Evidence (1)
- Observed
package-lock.json — meridian-auth@0.9.4 · lockfile.entry · dependencies.parse@1
Fingerprint fp_19cf85222bcfbde1 · rule v1
material SEC-033 Possible dependency confusion
Observedml/requirements.txt adds a private index with --extra-index-url. pip considers every index and installs the highest version, so a public package with the same name as a private one can be installed instead.
Evidence (1)
- Observed
ml/requirements.txt — --extra-index-url https://pypi.meridian.internal/simple · config.extra_index_url · supplychain.extra_index@1
Fingerprint fp_dcfba87d00eeeb25 · rule v1
material SEC-034 Dependency names resembling popular packages
Inferred1 direct dependency has a name one character away from a popular package (loadash). Confirm they are the intended packages.
Evidence (1)
- Observed
package-lock.json — loadash@1.0.0 · lockfile.entry · dependencies.parse@1
Fingerprint fp_9f36f7280727811f · rule v1
minor AI-004 Attribution records that cannot be checked
Unverifiable2 attribution record(s) could not be checked against the repository (unknown revision, missing file or out-of-range lines) and carry no weight.
Evidence (2)
- Unverifiable direct
src/billing/tax.ts @ deadbeefdead — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1 - Unverifiable direct
src/ai/summarize.ts @ 58d65e3e4738 — agent-trace 0.1.0 · provenance.agent_trace · ai.agent_trace@1
Fingerprint fp_2a7f642e89f66a95 · rule v1
minor AI-006 Large unattributed changes after AI tools were adopted
InferredCommit 81de5601f559 ("Add reporting module") added 950 lines across 10 files with no AI attribution, after AI tool configuration first appeared (2024-07-01). This is an inference, not evidence of AI origin; ask how it was produced.
Evidence (1)
- Inferred inference
commit 81de5601f559 — Add reporting module · commit.bulk_unattributed · ai.bulk_unattributed@1
Fingerprint fp_26573072b1008fc6 · rule v1
minor AID-002 Hard-coded model identifiers
Observed1 model identifier(s) are hard-coded (gpt-4o-2024-08-06). Providers retire model versions on their own schedule.
Evidence (1)
- Observed
src/ai/summarize.ts — gpt-4o-2024-08-06 · code.model_id · ai_dependency.model_id@1
Fingerprint fp_0ec97258e4f8bf6b · rule v1
minor MNT-002 Few or no tests
Derived1 test file(s) for 25 source files (4%).
Evidence (0)
No item-level evidence: this finding is derived from counts or configuration described in its summary.
Fingerprint fp_fe72c0e0b81ff642 · rule v1
minor OWN-006 Comments stating code was copied or adapted from a URL
Observed1 comment(s) say code was copied or adapted from an external URL (e.g. src/lib/parse.ts).
Evidence (1)
- Observed
src/lib/parse.ts:2 — Adapted from https://github.com/example/csv-lite/blob/main/parse.c · file.copied_from · thirdparty.copied_from@1
Fingerprint fp_b8c966ddde259430 · rule v1
minor REP-004 Container base images not pinned
ObservedDockerfile builds from python:3.12-slim, pinned by tag but not by digest.
Evidence (1)
- Observed
Dockerfile:5 — python:3.12-slim · container.base_image · reproducibility.docker@1
Fingerprint fp_78d21b97267087c1 · rule v1
minor REP-006 Toolchain versions not pinned
ObservedToolchain versions are not pinned for: Python (no .python-version or requires-python).
Evidence (0)
No item-level evidence: this finding is derived from counts or configuration described in its summary.
Fingerprint fp_1bb866e7d816d9ad · rule v1
minor REP-007 Build outputs committed to the repository
ObservedBuild output directories are committed: dist. Committed artifacts may not correspond to the committed source.
Evidence (1)
- Observed
dist · repo.build_output · inventory.build_output@1
Fingerprint fp_c8eeabe6abdf320f · rule v1
minor SEC-022 Third-party CI actions not pinned to a commit
Observed1 third-party action reference(s) are pinned to a tag or branch rather than a commit SHA (some-org/deploy-action@v2).
Evidence (1)
- Observed
.github/workflows/ci.yml:13 — some-org/deploy-action@v2 · ci.unpinned_action · ci.github_actions@1
Fingerprint fp_d8daffb1bdf1155b · rule v1
minor SEC-023 Pipelines pipe remote scripts to a shell
Observed1 pipeline or container file(s) pipe a downloaded script into a shell (.github/workflows/ci.yml).
Evidence (1)
- Observed
.github/workflows/ci.yml:17 — curl -sL https://get.example-cdn.io/setup.sh | bash · ci.pipe_to_shell · ci.pipe_to_shell@1
Fingerprint fp_13a446ca9cf1aa3c · rule v1
minor SEC-024 CI token granted write-all permissions
Observed.github/workflows/ci.yml grants the workflow token write-all permissions.
Evidence (0)
No item-level evidence: this finding is derived from counts or configuration described in its summary.
Fingerprint fp_0d06f7a88cd76b4a · rule v1
minor SEC-030 Production dependencies run install scripts
Observed1 production dependency runs install scripts (bcrypt@5.1.1).
Evidence (1)
- Observed
package-lock.json — bcrypt@5.1.1 · lockfile.entry · dependencies.parse@1
Fingerprint fp_6e7faed0bb6fb3dd · rule v1
info AI-001 AI coding tools used in this repository
ObservedEvidence of 5 AI coding tool(s): aider (1 attributed commit); chatgpt (file-comment); claude-code (2 attributed commits); cursor (2 attributed commits); github-copilot (1 attributed commit).
Evidence (5)
- Observed direct
commit 58d65e3e4738 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1 - Observed direct
commit 5f8ec9d222c4 — aider: · commit.ai_signal · ai.commit_signal@1 - Observed direct
commit 4c9a23cdf304 — Co-authored-by: Cursor Agent <cursoragent@cursor.com> · commit.ai_signal · ai.commit_signal@1 - Observed direct
commit d0bc1462d623 — Copilot <198982749+Copilot@users.noreply.github.com> · commit.ai_signal · ai.commit_signal@1 - Observed direct
commit 70ee954046d1 — Co-authored-by: Claude <noreply@anthropic.com> · commit.ai_signal · ai.commit_signal@1
Fingerprint fp_f76e52d6f06c1478 · rule v1
Suppressed by the company
minor SEC-001 Credential-like value in test or example code
Inferredsuppressed by companyHard-coded credential in test/billing.test.ts line 3 (test, example or placeholder value; confirm it is not live). The value is not reproduced here; fingerprint 1c26c5513f77abea.
Suppression reason (company-asserted): Test-only password used by the billing unit test; not a real credential. — security@meridian.io
Evidence (1)
- Inferred
test/billing.test.ts:3 — Hard-coded credential: test… (17 chars) · secret.match · secrets.generic-secret@1
Fingerprint fp_8a5d3f0986dc1ede · rule v1