Files
go-sip/docs/evidence/20260918-dependencies.md
T

64 lines
3.5 KiB
Markdown

# Local dependency inventory (2026-09-18)
This is a development inventory, not a production approval. Versions are from
`go.mod`/`go.sum`; license filenames were present in the local module cache.
`govulncheck` was rebuilt with Go 1.27.1 and reported no vulnerabilities for
this module on 2026-09-18. This is a point-in-time dependency scan, not a
production security approval; protocol PoC gates remain open.
| Module | Version | Local license file |
| --- | --- | --- |
| `github.com/rabbitmq/amqp091-go` | `v1.15.0` | `LICENSE` |
| `github.com/santhosh-tekuri/jsonschema/v6` | `v6.0.3` | `LICENSE` |
| `github.com/spf13/cobra` | `v1.10.1` | `LICENSE.txt` |
| `google.golang.org/grpc` | `v1.83.2` | `LICENSE` |
| `google.golang.org/protobuf` | `v1.36.12` | `LICENSE` |
| `modernc.org/sqlite` | `v1.59.0` | `LICENSE`, `LICENSE-SQLITE`, `LICENSE-SQLITE_VEC` |
| `github.com/pion/rtp` | `v1.10.5` | `LICENSE` |
| `github.com/zaf/g711` | `v1.4.0` | `LICENSE` |
| `github.com/shirou/gopsutil/v4` | `v4.26.8` | `LICENSE` |
| `github.com/aliyun/alibabacloud-oss-go-sdk-v2` | `v1.6.0` | `LICENSE` |
`github.com/shirou/gopsutil/v4 v4.26.8` is used for host/process resource
sampling; its local `LICENSE` SHA-256 is
`ad1e64b82c04fb2ee6bfe521bff01266971ffaa70500024d4ac767c6033aafb9`. The
sampler reports media-port and AI-provider quota dimensions as unknown until
those authoritative sources are connected.
The project now uses Pion RTP only through the thin bounded `internal/media`
policy adapter and `github.com/zaf/g711 v1.4.0` for A-law conversion; RTP wire
parsing and G.711 codec logic are not reimplemented. SIP/ARI, Asterisk
ExternalMedia, recording and the real media PoC remain blocked until the
approved media contract and compatibility gate are completed. No custom SIP,
ARI, RTP or RTCP protocol stack is used as a substitute.
The cached `github.com/zaf/g711 v1.4.0` license SHA-256 is
`2539ec80c8dd46ce74ba1fb145f270ce5c6f3df1fbe6132eed06e23e22edef48`.
The security scan used `govulncheck@v1.7.0` built with Go 1.27.1. Before
upgrading, it found reachable gRPC advisories in v1.79.3; upgrading to
`google.golang.org/grpc v1.83.2` and its compatible `golang.org/x/net v0.58.0`
/ `golang.org/x/text v0.41.0` closure produced a clean scan. The old scanner
binary had been built with Go 1.25 and was rebuilt rather than treating its
failure as a clean result.
Alibaba OSS is accessed through the official Go SDK and is used only by the
Dispatcher; Agents receive short-lived presigned grants and never receive AK/SK.
The project-owned static Cell artifact boundary is validated by
`internal/contract.ValidateStaticArtifact`: the imported schema is checked
first, then deployment-local Cell/source/digest/revision/egress/trunk bindings
are checked. This is a local contract guard only; it does not prove that
Asterisk loaded the artifact or that any SIP provider is reachable.
## 2026-09-19 physical Cell addendum
The physical deployment lock now includes Asterisk `22.10.1` source commit
`f0e408a7b0d829c85bf15fa4b487870a50cb3000`, source SHA-256
`373c98f4d4a1b923b42def0aee03f4e36aca9d1c244a8eeda646da8a97f89663`, bundled
Jansson `2.15.0`, bundled PJPROJECT `2.17`, and a native stage SHA-256
`68006a1a8efed288be4ca4a2ae3cb9554a31d733eac08eaacf4c646c95faf74d`. The
source/dependency archives and native stage are under `deploys/packages/`;
Asterisk was compiled directly on Debian 13 and started by physical systemd.
This locks the build input and install path, but does not replace management
approval of the static Cell configuration or supplier/media acceptance.