{
  "releaseSnapshot": {
    "format": "static-release-reference-v1",
    "sourceVersion": "0.29.0",
    "sourceRegistrySha256": "a2b5ec09bf6c38b9d2879d746a4fded374f5928b445377b0270ef6aa8e6cac65",
    "generatedAt": "2026-10-06T15:38:00Z",
    "releaseAcceptance": "not-verified-by-generator",
    "runtimeReadiness": "not-evaluated",
    "livePaymentsVerified": false,
    "indexingVerified": false,
    "apiOrigin": null,
    "notice": "Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment."
  },
  "exampleResponse": {
    "operation": "dependency-risk-flags",
    "version": "0.29.0",
    "result": {
      "dependencyCount": 2,
      "flaggedCount": 2,
      "dependencies": [
        {
          "index": 0,
          "name": "worker-kit",
          "flags": [
            "NON_EXACT_SEMVER",
            "INSECURE_SOURCE",
            "MISSING_INTEGRITY",
            "MISSING_LICENSE"
          ]
        },
        {
          "index": 1,
          "name": "private-plugin",
          "flags": [
            "LOCAL_SOURCE",
            "MISSING_INTEGRITY",
            "LICENSE_MARKER"
          ]
        }
      ],
      "scope": "Declared npm-style metadata checks only. Exact pin means canonical SemVer; integrity is syntax-checked, never verified against bytes. Flags are not vulnerabilities, trust scores, license advice, or security certification."
    },
    "provenance": {
      "inputSha256": "be895ca312990c168698ad23c01ab6760d8418b98486095625f41e3878f83b5e",
      "outputSha256": "e688f33b9caae1165e9f447518bd5bf579033cb1748934c640d652ee9080234b",
      "deterministic": true,
      "externalRequests": 0
    }
  }
}
