brand       : vara
version     : 3.21.0
built_at    : 2026-08-26T18:44:22.094Z
file        : index.html
bytes       : 3312390
sha256      : 622bc9ad69323c2ebd5ada85858cb319814cdf90bbe7fbbcbf28f10cfa7f4c96
gate_status : PASS

# Public security summary
  npm audit        : critical=0 high=0 moderate=0 low=0
  secret scan      : PASS
  provenance scan  : PASS
  artefact checks  : PASS
  CSP              : present
  network model    : standalone single-file HTML; no Versatile AI Risk Assessment vendor backend
  unsafe-eval      : blocked

# Residual notes
  - CSP contains `'unsafe-hashes'` — allowed for now (hash-pinned style attributes); becomes a hard error after C3-03.

# Notes
# Keep SECURITY.txt, RELEASE.txt, SBOM.cdx.json, VEX.cdx.json,
# SHA256SUMS.txt and index.html together for verification.
