GOLDEN PATH

Track 02A · Repos, dependencies + code as graphs

HydraBlast

Given a compromised package version, traverse the reverse dependency graph to identify exposed services, the exact dependency path, and whether a patch removes every vulnerable route.

RECEIPT_RECONCILIATION_REQUIRED_BEFORE_PUBLIC_PASSREAL NPM SNAPSHOT PENDING
01 / QUESTION

What is exposed at time T?

01Advisory
02PackageVersion
03DEPENDS_ON*
04Lockfile
05Service
02 / CANARY

Poison two paths. Repair one. Repair both.

Expected state trajectory

reference · 0→poison · 2→partial repair · 1→full repair · 0

Counts are exposed services in the synthetic structural canary, not real vulnerability counts.

Independent oracle

Python closure vs HydraDB.

Both consume the same frozen edge fixture. Exact exposed-service sets must match at every state before the public canary is green.

03 / CLAIM BOUNDARY

A synthetic blast radius is not a production vulnerability claim.

SYNTHETIC_TRACK02_STRUCTURAL_CANARY_ONLY_NOT_REAL_NPM_EXPOSURE

No real npm vulnerability, maintainer compromise or production exposure claim is made until the real data lane executes and its source/advisory/lockfile chain is retained.

04 / REAL-DATA GATE

Then replace the fixture with evidence.

Registry

npm

Exact package versions, dependencies and publication metadata.

Resolved graph

deps.dev

Resolved dependency relationships independently sourced from the package graph.

Advisories

OSV / GHSA

Affected and fixed version evidence; advisory existence is not treated as runtime exploit evidence.