Technical diligence dossier
Meridian Systems (synthetic demo company)
- Subject
meridian-systems/meridian-platform @ 5df5415bdef5- Produced by
- acquicode-engine 0.1.0, rules 2026.09.1
- Digest
c9f52a1b6dbe7ac7474f1c5a3bfb2a6fe27e15a50900861e9b0798b19489d655- Reproduce
- The same commits always give this digest. Hosted dossiers are also signed; anyone can verify one.
Meridian Systems does not exist. Its repository is generated by a script with deliberately planted problems (contractors without agreements, a live-looking key, copyleft dependencies, contradictory AI attribution, a vulnerable CI workflow) and then analysed by the same engine customers use.
4 findings must be resolved before close; 29 further material findings and 5 material unknowns remain.
- Strong copyleft (GPL-family) licenses in production dependencies
- Network copyleft (AGPL-family) licenses in production dependencies
- Credentials in the current code (2)
The level says how completely the evidence answers the diligence questions, not whether the software is good, secure or free of legal risk. AcquiCode does not run or test the code, audit its design, inspect infrastructure or data handling, or give legal advice, and it sees only the repositories listed under Scope.
How every claim is graded
Each finding, answer and piece of evidence carries one of these states. The readiness above can never be more certain than the weakest state it rests on.
- Verified
- Observed and independently checked
- Observed
- Read directly from the repository or a named source
- Derived
- Computed deterministically from observed facts
- Company-asserted
- Stated by the company; not proof
- Inferred
- Heuristic reading; raises questions, never blocks
- Conflicting
- Sources disagree
- Unknown
- No evidence either way
Unknowns are never counted as clean.
| Area | Unknown | Why | How to resolve | Material |
|---|---|---|---|---|
| ai development | Terms under which aider, cursor, github-copilot were used (plan tier, indemnity, filters) | The repository shows that a tool was used, not which account tier or settings applied. | Declare ai_tools in acquicode.yml with plan, indemnity and the contract that supports it. | yes |
| ai development | Whether pull requests containing AI-attributed changes were approved by another person | Review approvals live in the forge (GitHub/GitLab), not in git history. | Connect the GitHub App or GitLab token, or supply review exports. | yes |
| provenance | Origin and license of 1 committed binary file(s) | Binaries cannot be inspected like source code. | Provide the source or vendor/license information for each binary, or remove them. | yes |
| security | Known vulnerabilities in 2 dependencies without an exact version | No lockfile pins them, so the installed versions, and therefore the advisories that apply, cannot be determined. | Commit a lockfile and re-run the analysis. | yes |
| security | Known vulnerabilities in 10 dependency version(s) | Vulnerability enrichment (OSV) was not enabled for this analysis, so no advisories were checked. This is not the same as "no vulnerabilities". | Re-run with vulnerability enrichment enabled. | yes |
| security | Vulnerability and license status of 2 private package(s) | Private packages are never sent to external services. | Provide advisories or an SBOM for private packages. | no |
| security | Packages served from private indexes | Private package indexes are configured (ml/requirements.txt: https://pypi.meridian.internal/simple); their packages were not sent to any external service. | Provide an SBOM or license list for private packages. | no |
Coverage
- Files read in full
- 42 of 44
- History
- 19 commits
- Secrets in history
- 6 earlier file versions scanned
- Enrichment
- vulnerabilities: not enabled · package registries: not enabled · forge reviews: not connected