Skip to main content
Version: 2026.08.08

MCP docs SBOM and supply-chain notes

The machine-readable CycloneDX inventory for this release is published as /sbom.cdx.json and is generated from the locked npm dependency graph before deployment.

The documentation Worker serves static build output only and has no application runtime packages. Production runtime audit: 0 vulnerabilities (npm audit --omit=dev). Docusaurus 3.10.2 and its React/webpack toolchain are development-only build inputs; their current no-upstream-fix audit notices are never uploaded as executable Worker dependencies. Builds accept only reviewed repository assets and run in the governed release environment.

The MCP Worker and docs deployment use Cloudflare-managed bindings and secrets. Secret values are excluded from source, the SBOM, build output, and receipts.