# Dependency Metadata Flags

Build-time release reference. Runtime readiness, deployment, payment settlement and external indexing are not evaluated here. Prices are proposed; this file cannot authorize execution or payment.

Flag declared npm-style metadata gaps: missing/non-exact canonical SemVer pins, missing/insecure/local/unrecognized sources, missing/malformed or SHA1-only integrity, and missing license markers. Syntax/presence heuristics only; no vulnerability database, artifact verification, trust score or legal conclusion.

Release: 0.29.0. Built: 2026-10-06T15:38:00Z.

## Choose for
- Triage a bounded declared dependency list before human policy review
- Find missing pins, source declarations, integrity strings and license metadata

## Outside this profile
- Vulnerability or malware scanning, security certification, license compatibility decisions
- Treating absent flags as evidence a dependency is safe or authentic

Proposed nominal USD 0.005 per successful call; payer fees excluded. No verified runtime availability.

- [Exact release contract](/reference/services/dependency-risk-flags.json)
- [Input schema](/reference/schemas/dependency-risk-flags.input.json)
- [Output schema](/reference/schemas/dependency-risk-flags.output.json)
- [Fixed example](/reference/examples/dependency-risk-flags.json)
- [Complete HTML reference](/discover/tools/dependency-risk-flags)
