Skip to main content

Dependency override register

Tayho treats root dependency overrides as temporary, security-qualified controls. An override may be removed only after every direct owner has published a non-vulnerable compatible constraint and the frozen lockfile, workspace suite, Ponder runtime qualification, and four production image scans remain green without it. Qualification commands:
The release workflow additionally rebuilds and scans the keeper, indexer, API, and market-data images with pinned Grype. Do not add ignore rules to compensate for an override regression. The root package.json and frozen bun.lock are authoritative. Update this register in the same change as any override addition, version change, or removal.
Last modified on July 23, 2026