The identity of the dependency sets that decide what licenses/inventory.zon has to cover. This file is a snapshot, not a source: src/licenses_drift_test.zig recomputes each section from build.zig.zon and web/package-lock.json and fails when it disagrees with what is recorded here. Prose before the first section header is ignored by the guard. Updating a section without reviewing licenses/inventory.zon defeats the point of the guard. When a section changes, work out what the change means for the shipped bytes first, then record it. The runtime closure is every lockfile package not marked `dev`. That is a superset of what the bundler emits — the guard cannot run rollup — so packages tree-shaken out of web/dist appear here too; the inventory explains each of them instead of carrying its licence. The bundled-packages section is the one the Zig guard cannot compute: it is the set of npm packages that actually contribute a module to web/dist, read off the sourcemap `sources` lists of a `vite build --sourcemap`. Only the frontend gate can produce it, so gates.yml recomputes it there and fails on a difference. It is what closes the hole the runtime-closure section leaves open — a package already in the closure that application code starts importing changes no lockfile and no version, but it does change this list. The base image section is here for the same reason: the container image is a released artifact, and the one third-party file it carries that the binary does not — the Mozilla CA bundle — comes out of that base. A new tag or a rebuilt digest both change the line, which forces somebody to re-read what the new base ships before the inventory can claim it. The generators section is the other direction: packages the lockfile marks `dev` whose own output nevertheless ends up in web/dist, and so in the binary. Its membership is a judgement, not a query — it was settled by reading a `vite build --sourcemap` of web/, both the sourcemap `sources` lists and the regions of each chunk no sourcemap segment maps back to a source file. The versions here are read from the lockfile like any other section. [build.zig.zon dependencies] mbedtls url=https://github.com/Mbed-TLS/mbedtls/archive/refs/tags/mbedtls-3.6.7.tar.gz hash=N-V-__8AALrvlQKVtYlvv9dpBnbrJfdwR_F0wAgwsvZhAF1Y sqlite url=https://sqlite.org/2026/sqlite-amalgamation-3530400.zip hash=N-V-__8AAGVtrgCcOcmjrOJnagmnRyMrcKaOo09KbU-vu8w8 [npm runtime closure] @tanstack/history 1.162.0 MIT @tanstack/query-core 5.101.4 MIT @tanstack/react-query 5.101.4 MIT @tanstack/react-router 1.170.18 MIT @tanstack/react-store 0.9.3 MIT @tanstack/router-core 1.171.15 MIT @tanstack/store 0.9.3 MIT cookie-es 3.1.1 MIT isbot 5.2.1 Unlicense react 19.2.8 MIT react-dom 19.2.8 MIT scheduler 0.27.0 MIT seroval 1.5.6 MIT seroval-plugins 1.5.6 MIT use-sync-external-store 1.6.0 MIT [npm build-time generators whose output ships] rolldown 1.1.5 MIT tailwindcss 4.3.3 MIT vite 8.1.5 MIT [container base image] alpine:3.22@sha256:14358309a308569c32bdc37e2e0e9694be33a9d99e68afb0f5ff33cc1f695dce [npm packages bundled into web/dist] @tanstack/history @tanstack/query-core @tanstack/react-query @tanstack/react-router @tanstack/react-store @tanstack/router-core @tanstack/store react react-dom scheduler use-sync-external-store