Audit targets
Packages discovered across ecosystems, resolved to a source commit, and ranked by priority. This is the coverage gap — 7 uncovered targets awaiting an audit.
maven 2npm 2cargo 1go 1pypi 1
Claim the top-priority target — the CLI leases it and prints an audit playbook (clone, checkout, attest). Signing stays in the CLI; the browser never holds a key (contributor guide).
signet targets claim --registry <registry>
| Package | Source | Priority | Why (signals) | Coverage |
|---|---|---|---|---|
| npmevent-stream@3.3.6 | github.com/dominictarr/event-streame3163361fed01384… | 100 | TAMPERED | needs audit |
| npmexpress@5.1.0 | github.com/expressjs/express51a0e7c9d3f28b6a… | 158 | 1 advisory220,000 dependents66,000★scorecard 5.8 | needs audit |
| mavencom.fasterxml.jackson.core:jackson-databind@2.18.2 | github.com/FasterXML/jackson-databind287af92705039b2a… | 166 | 2 advisory95,000 dependents3,600★scorecard 6.5 | needs audit |
| mavenorg.springframework.boot:spring-boot@3.4.1 | github.com/spring-projects/spring-boot183285258d7b5092… | 174 | 1 advisory120,000 dependents75,000★scorecard 7.4 | needs audit |
| pypinumpy@2.2.0 | github.com/numpy/numpye7a123b2d3eca989… | 319 | 280,000 dependents28,000★scorecard 6.9 | needs audit |
| gogithub.com/spf13/cobra@1.8.1 | github.com/spf13/cobrae94f6d0dd9a5e573… | 324 | 38,000 dependents38,000★scorecard 6.1 | needs audit |
| cargotokio@1.42.0 | github.com/tokio-rs/tokiobb9d57017e100985… | 342 | 48,000 dependents27,000★scorecard 8.2 | needs audit |
The security-analysis subsystem leases these via POST /v1/targets/lease — highest priority first, uncovered only.