SEC / Security
Non-reproducible dependency resolution violates policy
portfolio.sec.25@1.0.0V-SEC-25 · Contract violation
Non-reproducible dependency resolution violates policy
Non-reproducible dependency resolution violates policy. It examines trust boundaries, sensitive flows, validation, and security-sensitive effects. The result remains unknown when the required evidence is incomplete.
Required evidence
The selected immutable build snapshot must provide complete source, sink, trust, policy, validation, and flow facts for this condition.
Safe cases and boundaries
When required evidence, source membership, or analysis-world closure is incomplete, the affected result remains unknown. Missing data alone is never a finding.
Current qualification
The source producer still requires recovery and qualification in this snapshot. The target description is not evidence of an active diagnostic.
Status and provenance
This page combines the reviewed rule identity with an English public description for catalog snapshot 4558458d. Changing status requires a new reviewed snapshot; page count is not a maturity claim.