Release digest
Fixed
- CRYPTO-SECURITY-PROVENANCE-ALIAS-DEPTH (Report Logic) — Crypto project
normalization now accepts attached non-audit security provenance payloads as
security_evidence, including security attestations, certifications, compliance reports, and bug bounty program records. - Downloadable report view models can now use those normalized rows to clear
false
Security evidence depthgaps when provider, scope, date, or status context is attached in Vartovii data.
Internal
- Added normalizer and PDF view-model regression coverage for attestation, certification, and bug bounty security evidence aliases, including raw URL suppression and non-audit boundary preservation.
- Updated
docs/architecture/CRYPTO_REPORTS.md,docs/reports/audits/2026-06-01_CRYPTO_REPORT_DATA_GAP_ANALYSIS.md, andknowledge-base/docs/crypto/dashboard-ui.mdto document the additional security provenance aliases. Public docs decision: public crypto docs were updated because visible downloadable PDF security-evidence semantics changed; no audit completion, remediation verification, safety, legal, billing, or investment claims were added.