{"schema":7,"target":"level dependency","subject":"monumental-archive/stele","verdict":"PASS","population":{"size":1,"expected":1,"source":"declared","detail":"repository with a determinable ladder"},"facts":[{"name":"level","value":"SLSA_DEPENDENCY_LEVEL_2"},{"name":"specStatus","value":"draft"},{"name":"ladder","value":"1:HELD 2:HELD 3:REFUTED 4:UNDETERMINED"},{"name":"sealedAt","value":"2026-08-24T05:45:40Z"},{"name":"dependency/inventory","value":"HELD: a published inventory covers all 4 published artifact(s)"},{"name":"dependency/scanned","value":"HELD: the inventories covering 4 published artifact(s) were scanned against a vulnerability database, identifying 0 finding(s)"},{"name":"dependency/triaged","value":"HELD: the scan identified no known vulnerability in the publish's inventories"},{"name":"dependency/producer-controlled","value":"REFUTED: 1 resolved dependency source(s) are upstream rather than producer-controlled: [the default golang registry] — the specification requires: The build process MUST consume all third-party build dependencies only from artifact producer-controlled locations, instead of directly from upstream."},{"name":"dependency/secure-ingestion","value":"UNDETERMINED: no dependency shipped sooner than 247h0m0s after it was published (pkg:golang/golang.org/x/mod@v0.40.0 was the soonest, across 79 resolved) — consistent with an ingestion control, but a slow release cadence leaves the same interval, so the policy's enforcement is not established from this alone"},{"name":"requirementCoverage","value":"5/5"}]}