From 967e5c692219103baaac504570d375a441fd27f4 Mon Sep 17 00:00:00 2001 From: Affaan Mustafa Date: Wed, 13 May 2026 07:15:13 -0400 Subject: [PATCH] docs: mark JARVIS backend audit clean --- docs/ECC-2.0-GA-ROADMAP.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/docs/ECC-2.0-GA-ROADMAP.md b/docs/ECC-2.0-GA-ROADMAP.md index 1f685daa..4ca7601f 100644 --- a/docs/ECC-2.0-GA-ROADMAP.md +++ b/docs/ECC-2.0-GA-ROADMAP.md @@ -61,7 +61,8 @@ As of 2026-05-13: records the May 13 supply-chain sweep: no active lockfile/manifest hit for TanStack/Mini Shai-Hulud indicators; npm audit/signature checks clean across active npm lockfiles; `cargo audit` clean for `ecc2`; trunk `pip-audit` - clean; JARVIS backend Python audit blocked by unresolved `mediapipe==0.10.32`. + clean; JARVIS backend pinned-graph Python audit clean under the supported + Python 3.12 target. - Local PR #1861 validation refreshed `node scripts/harness-audit.js --format json` at 70/70 and `npm run observability:ready` at 21/21. - `ECC-Tools` has a local-only hardening branch