Dependency Audit
Use existing project package managers and lockfiles. Read references/reporting.md for the report shape. references/legacy/ is archival only.
Workflow
- Detect package ecosystems and lockfiles.
- Prefer local audit commands already available in the repo.
- Do not install new audit tools without approval.
- Summarize critical/high vulnerabilities, license blockers, unused dependencies, and upgrade pressure.
- Distinguish exploitable production risk from irrelevant dev-only noise.