Expected state trajectory
Counts are exposed services in the synthetic structural canary, not real vulnerability counts.
Track 02A · Repos, dependencies + code as graphs
Given a compromised package version, traverse the reverse dependency graph to identify exposed services, the exact dependency path, and whether a patch removes every vulnerable route.
Expected state trajectory
Counts are exposed services in the synthetic structural canary, not real vulnerability counts.
Independent oracle
Both consume the same frozen edge fixture. Exact exposed-service sets must match at every state before the public canary is green.
SYNTHETIC_TRACK02_STRUCTURAL_CANARY_ONLY_NOT_REAL_NPM_EXPOSURE
No real npm vulnerability, maintainer compromise or production exposure claim is made until the real data lane executes and its source/advisory/lockfile chain is retained.
Registry
Exact package versions, dependencies and publication metadata.
Resolved graph
Resolved dependency relationships independently sourced from the package graph.
Advisories
Affected and fixed version evidence; advisory existence is not treated as runtime exploit evidence.