veritas_dependency_gate
Evaluate third-party dependency risk for deployment by scanning SBOM, checking CVEs, verifying integrity, reviewing licenses, and analyzing dependency depth. Returns a verdict and per-dependency findings.
Instructions
Gate 3/10: Analyzes supply-chain security via SBOM scan, CVE check, integrity verification, license compatibility, and dependency depth. Use this to assess third-party dependency risk before deploying or releasing. Returns JSON with verdict (PASS | MODEL_BOUND | VIOLATION) and per-dependency findings array.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| claim | Yes | A VERITAS BuildClaim object for deterministic gate evaluation. All fields are optional for partial evaluation — only fields relevant to the invoked gate are required. |