{"passed": false, "timestamp": "2026-08-19T11:34:04+02:00", "scope": "full development tree audit", "command": "npm audit --registry=https://registry.npmjs.org/", "vulnerabilities": {"info": 0, "low": 0, "moderate": 9, "high": 7, "critical": 0, "total": 16}, "packages": ["adm-zip (high)", "fast-xml-parser (high)", "sharp (high, libvips CVEs)", "@opentelemetry/core (moderate)", "tar (moderate)"], "reach": "dev-only; every advisory is transitive under the @oh-my-pi/* peer SDK. npm audit --omit=dev reports 0 vulnerabilities, so no advisory reaches the published tarball (runtime deps are crc-32, yauzl, yazl).", "remediation": "none available in-window: npm audit fix --dry-run changes 0 packages and still reports 16. Requires an upstream @oh-my-pi release; forcing it would leave the >=16.4.6 <17 peer window."}