{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=pugarhuda/dependency-trust-diff@0.8.4","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"For every dependency your lockfile pins — npm, pnpm and yarn, PyPI, crates.io and Go — compare the version you actually have against the public registry and report what a version number hides — the publishing account changed, the license changed, an install hook appeared, or a known vulnerability already sits on the exact version you pinned. Read-only, no credentials, no adapters, and nothing the repository ships is ever executed. A package name stays the same through a maintainer handover, a sold project, or a takeover, so the name is not the supply-chain trust anchor; the publishing account and the license are, and neither appears in \u0060npm outdated\u0060 or a lockfile diff. Reads package-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml (v5 to v9) and yarn.lock (classic and berry), for Python projects uv.lock, poetry.lock, Pipfile.lock or a ==-pinned requirements.txt, for Rust projects Cargo.lock, and for Go projects go.mod — direct dependencies by default, scope=all for the whole tree — asks registry.npmjs.org, pyp","distribution":{"digest":"sha256:ada8a3679710b8ee419464de5b31832ab0c981c2d1f8eec74ffd00fbc3b36f7f","mediaType":"application/vnd.modiqo.rote-flow","size":16483,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4.json"},"name":"dependency-trust-diff","owner":{"kind":"user","slug":"pugarhuda"},"parameters":[{"description":"Project to check: a git URL (https://, ssh://, git@host:owner/name) or a path to a local checkout with an npm, pnpm, yarn, uv, poetry, pip, Cargo or Go module file","example":"https://github.com/axios/axios","input":{"allowCustom":true,"choices":[],"label":"Repo"},"name":"repo","required":true,"type":"string"},{"description":"Branch or tag to inspect. Ignored for a local path; defaults to the repository default branch.","input":{"allowCustom":true,"choices":[],"label":"Branch"},"name":"branch","required":false,"type":"string"},{"default":"direct","description":"\u0060direct\u0060 checks only the root package.json dependencies; \u0060all\u0060 checks every package the lockfile pins","input":{"allowCustom":true,"choices":[],"label":"Scope"},"name":"scope","required":false,"type":"string"},{"default":"200","description":"Upper bound on packages queried (two registry GETs each). Packages beyond it are counted as skipped, never assumed fine.","input":{"allowCustom":true,"choices":[],"label":"Max packages"},"name":"max_packages","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4","headlessCommandTemplate":"rote play run https://play.modiqo.ai/pugarhuda/dependency-trust-diff@0.8.4 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.79.0"},"publishedAt":"2026-09-06T15:46:48.322792+00:00","reference":"pugarhuda/dependency-trust-diff@0.8.4","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"hostToolRequirements":[{"command":"python3","required":true,"versionRequirement":null},{"command":"sh","required":true,"versionRequirement":null},{"command":"git","required":true,"versionRequirement":null},{"command":"mktemp","required":true,"versionRequirement":null},{"command":"tr","required":true,"versionRequirement":null}],"localTools":["python3","sh","git","mktemp","tr"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":0,"installs":0},"steps":{"count":2,"names":["diff","resolve"]},"title":"dependency-trust-diff","type":"play","version":"0.8.4","visibility":"public"}