Audit targets

Packages discovered across ecosystems, resolved to a source commit, and ranked by priority. This is the coverage gap — 7 uncovered targets awaiting an audit.

maven 2npm 2cargo 1go 1pypi 1

Claim the top-priority target — the CLI leases it and prints an audit playbook (clone, checkout, attest). Signing stays in the CLI; the browser never holds a key (contributor guide).

signet targets claim --registry <registry>
PackageSourcePriorityWhy (signals)Coverage
npmevent-stream@3.3.6github.com/dominictarr/event-stream
e3163361fed01384…
100
TAMPERED
needs audit
npmexpress@5.1.0github.com/expressjs/express
51a0e7c9d3f28b6a…
158
1 advisory220,000 dependents66,000scorecard 5.8
needs audit
mavencom.fasterxml.jackson.core:jackson-databind@2.18.2github.com/FasterXML/jackson-databind
287af92705039b2a…
166
2 advisory95,000 dependents3,600scorecard 6.5
needs audit
mavenorg.springframework.boot:spring-boot@3.4.1github.com/spring-projects/spring-boot
183285258d7b5092…
174
1 advisory120,000 dependents75,000scorecard 7.4
needs audit
pypinumpy@2.2.0github.com/numpy/numpy
e7a123b2d3eca989…
319
280,000 dependents28,000scorecard 6.9
needs audit
gogithub.com/spf13/cobra@1.8.1github.com/spf13/cobra
e94f6d0dd9a5e573…
324
38,000 dependents38,000scorecard 6.1
needs audit
cargotokio@1.42.0github.com/tokio-rs/tokio
bb9d57017e100985…
342
48,000 dependents27,000scorecard 8.2
needs audit

The security-analysis subsystem leases these via POST /v1/targets/lease — highest priority first, uncovered only.