Package Evaluation

Third-party package evaluation & security scan workspace · same console as factory, pipelines, and gates

Host GitLab Connection: GitLab environment not configured

Live Data Unavailable

Project ID: not configured · Repository: Not available until the host .env is configured

GitLab Live Runs
0
Host .env connected
Active / Running
0
Live CI/CD jobs executing
Failed Jobs / Runs
0
Control gate & runner errors
Ledger Inventory
6
Scanned artifacts & packages
Pending HITL
2
Awaiting ISSO disposition
1. Dependency & Package Scanner
Enter a GitHub repo (`owner/repo`), package ref (`npm:express@4.18.2`, `pypi:requests`), Maven coordinate (`group:artifact:version`), or Conan ref. Ecosystem is auto-detected.
Detected: GitHub Repository
Showing 6 of 6 ledger items
Artifact / RepoEcosystemLicense / OSICritHighGateLedger Note & SignatureHITL Action
8.4.0-1.el9 · dadsocSTL/gitlab-idp-platform
rpmcurl (MIT-style)ApprovedZero High/Critical. ISSO countersigned on the factory ledger.
2.32.3 · dadsocSTL/gitlab-idp-platform
pypiApache-2.0ApprovedClean scan. Published to the mission Python base layer.
1.2.11-17.el9 · dadsocSTL/gitlab-idp-platform
rpmZlib1HeldCVE-2022-37434 HIGH — fail-closed. Needs exception or 1.2.12 backport.
2.14.1 · dadsocSTL/gitlab-idp-platform
mavenApache-2.011HeldLog4Shell CRITICAL. Quarantine until 2.17.1.
mapped · IBM/compliance-trestle
repoApache-2.0ApprovedCaC/OSCAL tooling reused by Trestle Forge. Not a second estate.
mapped · ComplianceAsCode/content
repoBSD-3-ClauseApprovedSSG source reused by the factory import path. Not a second estate.