Dependency profile
- Dependency owner
- Plural maintainers, repositories and authorized release authorities
- Affected population
- All dependent services and operators
- Substitutability
- CONSTRAINED
- Switching cost
- VERY_HIGH
- Replacement time
- Scenario-specific; must be measured and tested, not assumed.
- Concentration level
- VERY_HIGH
- Non-Domination Test
- PASS_REQUIREMENTS_DEFINED
Abuse and failure paths
Abuse: Forced updates, hidden telemetry, license coercion, model manipulation and single-maintainer control.
Failure: Supply-chain compromise, abandoned dependency, incompatible release or systemic defect.
Required exit and alternatives
Exit: Source escrow or open source where appropriate, reproducible builds, rollback, forkability and alternate maintainers.
Portability: Portable source, models, configuration, data and deterministic build instructions within lawful limits.
Interoperability: Open protocols, file formats, SBOM/AIBOM and update metadata.
Independent alternative: Independent implementation, stable previous version and manual fallback.
Emergency handback: Freeze release channel, isolate affected workloads, restore attested last-known-good and publish correction.
Disconfirming evidence
- Failed exit drill
- Unavailable independent alternative
- Retaliation for attempted exit
- Material portability gap
- Undisclosed common-mode dependency
Truth boundary
Static risk-governance record. It does not prove an operational service, market share, capacity, dependency, alternative, or successful exit drill.
Authority and record status
Responsible authority: National Engineering Directorate and affected service authority.
Static concentration-governance record; no operational alternative or exit drill is proven.
Revision date: . Public corrections may be initiated through the diplomatic contact route.