Claims and observations stay separate.
PASS is used only when there is a verifiable chain. An endpoint response is not uptime, a configured verify command is not a successful release, and unavailable external checks are never presented as success.
—
No PASS; attestation chain is incomplete.
External verification unavailable.
Independent MDN result unavailable.
Release attestation chain
The attestation is written only after the initial production build, TypeScript, ESLint, Bun tests and critical route verification succeed. A second/final Vite build then embeds it into the deploy artifact.
Supply chain
The public surface does not disclose dependency names or CVE/OSV identifiers. OSV results are aggregated. This is not a full transitive vulnerability audit or penetration test.
We do not manufacture our own security grade.
When MDN HTTP Observatory is reachable, its own grade/score is displayed. Otherwise the state remains UNKNOWN. Local header heuristics are not blended into the MDN result.