brand       : vara
version     : 3.21.0
built_at    : 2026-08-26T18:44:06.336Z
file        : index.html
bytes       : 4828758
sha256      : 19a8e3b07fcbf81de23237105fae178c075cca2872729f9a2f84870cdf7052ac
gate_status : PASS

# Public security summary
  npm audit        : critical=0 high=0 moderate=0 low=0
  secret scan      : PASS
  provenance scan  : PASS
  artefact checks  : PASS
  CSP              : present
  network model    : standalone single-file HTML; no Versatile AI Risk Assessment vendor backend
  unsafe-eval      : blocked

# Residual notes
  - CSP contains `'unsafe-hashes'` — allowed for now (hash-pinned style attributes); becomes a hard error after C3-03.

# Notes
# Keep SECURITY.txt, RELEASE.txt, SBOM.cdx.json, VEX.cdx.json,
# SHA256SUMS.txt and index.html together for verification.
