chainstrip Book a demo

case study

Cal.com's OSS release · production Next.js monorepo, our primary testbed

TypeScriptNext.jsYarn 4 workspacesvitestPlaywright

103of 189 advisories never enter the artifact
1live HIGH eliminated, gate green
2real bugs surfaced by generated tests
dependencies
232 runtime dependencies (262 imported overall)
test suite
406 test files, plus a Playwright e2e suite
installed
3.3 GB installed node_modules
build oracle
Next.js production build as second oracle

measured on upstream commit 180ede28 of 2026-05-15

Cal.diy is the open-source release of Cal.com's scheduling product: a production Next.js monorepo on Yarn 4 workspaces, 232 runtime dependencies, 406 test files plus a Playwright e2e suite, and a build that fails loudly. It has been ChainStrip's primary testbed since June — every mechanism on the main page was measured here first — which makes it the study with the longest history behind it: the wins, the holds, and every verdict below come from one current run on the same tree we've measured since June.

Day one

The cold scorer read the full install — 3.3 GB, dev toolchain included — in about three minutes:

day one — the full score output, all 3,524 cards, worst first (re-run 2026-07-28; scroll inside)
$ chainstrip score --dir .

querying OSV: 188 advisories across 90 packages...

3524 packages — A 3248 · B 201 · C 47 · D 18 · F 10
90 with known CVEs · 24 with install scripts · 26 with native code

F  axios@1.15.0
   28 CVEs: 11 HIGH, 16 MODERATE, 1 LOW
   surface: network
F  hono@4.12.12
   18 CVEs: 1 HIGH, 16 MODERATE, 1 LOW
   surface: network · dynamic-import · fs-write
F  next@16.2.3
   22 CVEs: 11 HIGH, 9 MODERATE, 2 LOW
   surface: obfuscation · eval · process.binding · child_process · dynamic-require · network · dynamic-import · fs-write · bin
F  protobufjs@7.5.5
   11 CVEs: 5 HIGH, 6 MODERATE
   surface: install-script · eval · dynamic-require · network
F  tar@7.5.11
   6 CVEs: 1 CRITICAL, 1 HIGH, 4 MODERATE
   surface: fs-write
F  fast-uri@3.1.0
   4 CVEs: 4 HIGH
   surface: network
F  @xmldom/xmldom@0.9.9
   4 CVEs: 4 HIGH
   surface: none
F  @xmldom/xmldom@0.8.12
   4 CVEs: 4 HIGH
   surface: none
F  dompurify@3.3.2
   13 CVEs: 9 MODERATE, 4 LOW
   surface: none
F  next-auth@4.24.13
   3 CVEs: 1 CRITICAL, 1 HIGH, 1 MODERATE
   surface: network
D  i18next-fs-backend@2.6.0
   2 CVEs: 1 CRITICAL, 1 HIGH
   surface: dynamic-import · fs-write
D  nodemailer@7.0.12
   6 CVEs: 1 HIGH, 4 MODERATE, 1 LOW
   surface: child_process · network · fs-write
D  vite@6.4.2
   2 CVEs: 1 HIGH, 1 MODERATE
   surface: obfuscation · eval · process.binding · child_process · dynamic-require · network · dynamic-import · fs-write · bin
D  shell-quote@1.8.2
   2 CVEs: 1 CRITICAL, 1 HIGH
   surface: none
D  vitest@4.0.16
   1 CVEs: 1 CRITICAL
   surface: child_process · dynamic-require · network · dynamic-import · fs-write · bin
D  sharp@0.33.5
   1 CVEs: 1 HIGH
   surface: install-script · native · child_process · dynamic-require · network · fs-write
D  sharp@0.34.5
   1 CVEs: 1 HIGH
   surface: install-script · native · child_process · dynamic-require · network · fs-write
D  websocket-driver@0.7.4
   2 CVEs: 1 CRITICAL, 1 MODERATE
   surface: network
D  brace-expansion@1.1.11
   4 CVEs: 2 HIGH, 1 MODERATE, 1 LOW
   surface: none
D  prisma@6.16.1
   no known CVEs
   surface: install-script · obfuscation · eval · process.binding · child_process · dynamic-require · network · dynamic-import · fs-write · bin
D  brace-expansion@5.0.5
   3 CVEs: 2 HIGH, 1 MODERATE
   surface: none
D  dompurify@3.4.0
   9 CVEs: 5 MODERATE, 4 LOW
   surface: none
D  postcss@8.5.6
   3 CVEs: 2 HIGH, 1 MODERATE
   surface: none
D  postcss@8.4.31
   3 CVEs: 2 HIGH, 1 MODERATE
   surface: none
D  @grpc/grpc-js@1.12.6
   2 CVEs: 2 HIGH
   surface: network
D  brace-expansion@2.0.3
   2 CVEs: 2 HIGH
   surface: none
D  immutable@3.8.3
   2 CVEs: 2 HIGH
   surface: none
D  linkify-it@5.0.0
   2 CVEs: 2 HIGH
   surface: none
C  esbuild@0.23.1
   1 CVEs: 1 MODERATE
   surface: install-script · child_process · dynamic-require · network · fs-write · bin
C  mermaid@11.14.0
   4 CVEs: 4 MODERATE
   surface: network
C  @prisma/client@6.16.1
   no known CVEs
   surface: install-script · obfuscation · child_process · dynamic-require · network · fs-write
C  deasync@0.1.31
   no known CVEs
   surface: install-script · native · child_process · dynamic-require · network · fs-write
C  typeorm@0.3.27
   2 CVEs: 2 MODERATE
   surface: child_process · dynamic-require · network · dynamic-import · fs-write · bin
C  effect@3.16.12
   1 CVEs: 1 HIGH
   surface: eval · network · fs-write
C  effect@3.19.4
   1 CVEs: 1 HIGH
   surface: eval · network · fs-write
C  effect@3.18.4
   1 CVEs: 1 HIGH
   surface: eval · network · fs-write
C  ws@8.18.3
   2 CVEs: 1 HIGH, 1 MODERATE
   surface: network
C  ws@8.17.1
   2 CVEs: 1 HIGH, 1 MODERATE
   surface: network
C  @prisma/engines@5.22.0
   no known CVEs
   surface: install-script · native · child_process · dynamic-require · fs-write
C  @prisma/engines@6.15.0
   no known CVEs
   surface: install-script · native · child_process · dynamic-require · fs-write
C  @prisma/engines@6.16.1
   no known CVEs
   surface: install-script · native · child_process · dynamic-require · fs-write
C  @prisma/engines@6.16.2
   no known CVEs
   surface: install-script · native · child_process · dynamic-require · fs-write
C  @sentry-internal/node-cpu-profiler@2.2.0
   no known CVEs
   surface: install-script · native · child_process · dynamic-require · fs-write
C  js-yaml@4.1.1
   2 CVEs: 1 HIGH, 1 MODERATE
   surface: bin
C  msw@2.7.0
   no known CVEs
   surface: install-script · eval · child_process · network · fs-write · bin
C  multer@2.1.1
   2 CVEs: 1 HIGH, 1 MODERATE
   surface: fs-write
C  tmp@0.0.33
   2 CVEs: 1 HIGH, 1 LOW
   surface: process.binding · fs-write
C  webpack@5.104.1
   no known CVEs
   surface: obfuscation · eval · child_process · dynamic-require · network · dynamic-import · fs-write · bin
C  svgo@4.0.1
   1 CVEs: 1 HIGH
   surface: network · dynamic-import · fs-write · bin
C  @parcel/watcher@2.5.1
   no known CVEs
   surface: install-script · native · child_process · dynamic-require
C  kysely@0.28.14
   1 CVEs: 1 HIGH
   surface: dynamic-require · network · dynamic-import
C  @depot/cli@0.0.1-cli.2.80.0
   no known CVEs
   surface: install-script · child_process · dynamic-require · network · fs-write · bin
C  @nestjs/core@10.4.20
   1 CVEs: 1 MODERATE
   surface: install-script · dynamic-require · network
C  esbuild@0.25.12
   no known CVEs
   surface: install-script · child_process · dynamic-require · network · fs-write · bin
C  msgpackr-extract@3.0.3
   no known CVEs
   surface: install-script · native · child_process · bin
C  @sentry/cli@2.58.4
   no known CVEs
   surface: install-script · child_process · network · fs-write · bin
C  yarn@1.22.19
   no known CVEs
   surface: install-script · child_process · dynamic-require · fs-write · bin
C  @swc/core@1.15.8
   no known CVEs
   surface: install-script · child_process · dynamic-require · fs-write
C  engine.io@6.5.5
   1 CVEs: 1 HIGH
   surface: network
C  form-data@4.0.4
   1 CVEs: 1 HIGH
   surface: network
C  playwright@1.57.0
   no known CVEs
   surface: eval · child_process · dynamic-require · network · dynamic-import · fs-write · bin
C  prettier@3.6.2
   no known CVEs
   surface: eval · child_process · dynamic-require · network · dynamic-import · fs-write · bin
C  rollup@4.59.0
   no known CVEs
   surface: eval · child_process · dynamic-require · network · dynamic-import · fs-write · bin
C  ws@7.5.10
   1 CVEs: 1 HIGH
   surface: network
C  glob@10.4.5
   1 CVEs: 1 HIGH
   surface: bin
C  glob@10.3.1
   1 CVEs: 1 HIGH
   surface: bin
C  glob@10.3.10
   1 CVEs: 1 HIGH
   surface: bin
C  tmp@0.2.5
   1 CVEs: 1 HIGH
   surface: fs-write
C  @lingo.dev/_compiler@0.8.6
   no known CVEs
   surface: eval · child_process · dynamic-require · network · dynamic-import · fs-write
C  @oclif/core@1.26.2
   no known CVEs
   surface: eval · child_process · dynamic-require · network · dynamic-import · fs-write
C  playwright-core@1.57.0
   no known CVEs
   surface: eval · child_process · dynamic-require · network · fs-write · bin
C  fast-xml-builder@1.1.4
   1 CVEs: 1 HIGH
   surface: none
C  js-cookie@2.2.1
   1 CVEs: 1 HIGH
   surface: none
C  js-cookie@3.0.5
   1 CVEs: 1 HIGH
   surface: none
C  sqlite3@5.1.7
   no known CVEs
   surface: install-script · native
B  @prisma/get-platform@6.15.0
   no known CVEs
   surface: eval · process.binding · child_process · fs-write
B  @prisma/get-platform@6.16.1
   no known CVEs
   surface: eval · process.binding · child_process · fs-write
B  @prisma/get-platform@6.16.2
   no known CVEs
   surface: eval · process.binding · child_process · fs-write
B  @prisma/internals@5.22.0
   no known CVEs
   surface: eval · child_process · dynamic-require · network · fs-write
B  @prisma/internals@6.15.0
   no known CVEs
   surface: eval · child_process · dynamic-require · network · fs-write
B  @prisma/internals@6.16.2
   no known CVEs
   surface: eval · child_process · dynamic-require · network · fs-write
B  dotenv-checker@1.1.5
   no known CVEs
   surface: install-script · dynamic-require · fs-write · bin
B  esm@3.2.25
   no known CVEs
   surface: process.binding · child_process · dynamic-require · network · dynamic-import
B  checkly@4.2.0
   no known CVEs
   surface: eval · dynamic-require · network · dynamic-import · fs-write · bin
B  core-js@3.39.0
   no known CVEs
   surface: install-script · network · fs-write
B  giget@2.0.0
   no known CVEs
   surface: process.binding · child_process · network · fs-write · bin
B  @graphql-codegen/cli@5.0.5
   no known CVEs
   surface: child_process · dynamic-require · network · dynamic-import · fs-write · bin
B  @unkey/api@2.0.3
   no known CVEs
   surface: eval · process.binding · network · bin
B  d3@7.9.0
   no known CVEs
   surface: obfuscation · eval · network
B  dub@0.59.1
   no known CVEs
   surface: eval · process.binding · network · bin
B  dub@0.61.14
   no known CVEs
   surface: eval · process.binding · network · bin
B  prettier@2.8.7
   no known CVEs
   surface: child_process · dynamic-require · network · dynamic-import · fs-write · bin
B  @oclif/core@2.8.11
   no known CVEs
   surface: eval · dynamic-require · network · dynamic-import · fs-write
B  @prisma/fetch-engine@5.22.0
   no known CVEs
   surface: eval · child_process · network · fs-write
B  @sentry/node-core@9.46.0
   no known CVEs
   surface: obfuscation · child_process · network
B  @sentry/node-core@10.33.0
   no known CVEs
   surface: obfuscation · child_process · network
B  file-type@20.4.1
   2 CVEs: 2 MODERATE
   surface: none
B  import-in-the-middle@1.13.1
   no known CVEs
   surface: eval · child_process · dynamic-require · dynamic-import
B  mathjax-full@3.2.2
   no known CVEs
   surface: eval · dynamic-require · network · dynamic-import · fs-write
B  react-devtools-core@4.28.4
   no known CVEs
   surface: eval · child_process · network · dynamic-import
B  @ardatan/relay-compiler@12.0.3
   no known CVEs
   surface: eval · child_process · fs-write · bin
B  ejs@3.1.10
   no known CVEs
   surface: eval · child_process · fs-write · bin
B  typescript@5.3.3
   no known CVEs
   surface: child_process · dynamic-require · network · fs-write · bin
B  @mixmark-io/domino@2.2.0
   no known CVEs
   surface: eval · dynamic-require · network · fs-write
B  ajv@6.14.0
   no known CVEs
   surface: eval · dynamic-require · network · fs-write
B  bcryptjs@2.4.3
   no known CVEs
   surface: eval · dynamic-require · network · fs-write
B  chevrotain@10.5.0
   no known CVEs
   surface: eval · process.binding · fs-write
B  jsdom@22.0.0
   no known CVEs
   surface: eval · child_process · network
B  jsdom@25.0.1
   no known CVEs
   surface: eval · child_process · network
B  prismjs@1.30.0
   no known CVEs
   surface: eval · dynamic-require · network · dynamic-import
B  trigger.dev@4.3.2
   no known CVEs
   surface: child_process · network · dynamic-import · fs-write · bin
B  ts-node@10.9.2
   no known CVEs
   surface: child_process · dynamic-require · dynamic-import · fs-write · bin
B  speech-rule-engine@4.1.3
   no known CVEs
   surface: eval · network · fs-write · bin
B  terser@5.46.1
   no known CVEs
   surface: eval · network · fs-write · bin
B  vite-plugin-inspect@0.8.4
   no known CVEs
   surface: eval · network · dynamic-import · fs-write
B  webpack-bundle-analyzer@4.10.1
   no known CVEs
   surface: eval · network · fs-write · bin
B  xml2js@0.6.2
   no known CVEs
   surface: eval · child_process · fs-write
B  @boxyhq/saml-jackson@1.52.2
   no known CVEs
   surface: eval · dynamic-require · network
B  @changesets/cli@2.29.4
   no known CVEs
   surface: child_process · dynamic-require · fs-write · bin
B  @nestjs/cli@10.3.2
   no known CVEs
   surface: child_process · dynamic-require · fs-write · bin
B  fast-xml-parser@5.5.9
   1 CVEs: 1 MODERATE
   surface: fs-write · bin
B  giget@1.2.5
   no known CVEs
   surface: child_process · network · fs-write · bin
B  jake@10.8.7
   no known CVEs
   surface: child_process · dynamic-require · fs-write · bin
B  lingo.dev@0.117.14
   no known CVEs
   surface: child_process · network · fs-write · bin
B  markdown-it@14.1.1
   1 CVEs: 1 MODERATE
   surface: fs-write · bin
B  marked@15.0.6
   no known CVEs
   surface: child_process · dynamic-require · fs-write · bin
B  marked@16.4.2
   no known CVEs
   surface: child_process · dynamic-require · fs-write · bin
B  node-gyp@10.2.0
   no known CVEs
   surface: child_process · network · fs-write · bin
B  node-gyp@8.4.1
   no known CVEs
   surface: child_process · network · fs-write · bin
B  node-gyp@9.3.1
   no known CVEs
   surface: child_process · network · fs-write · bin
B  retry@0.12.0
   no known CVEs
   surface: eval · dynamic-require · network
B  sucrase@3.34.0
   no known CVEs
   surface: eval · dynamic-import · fs-write · bin
B  turbo@2.7.1
   2 CVEs: 1 MODERATE, 1 LOW
   surface: bin
B  typescript@5.9.3
   no known CVEs
   surface: child_process · network · fs-write · bin
B  typescript@5.9.2
   no known CVEs
   surface: child_process · network · fs-write · bin
B  typescript@5.8.2
   no known CVEs
   surface: child_process · network · fs-write · bin
B  @apm-js-collab/code-transformer@0.8.2
   no known CVEs
   surface: obfuscation · dynamic-require
B  @hono/node-server@1.19.13
   1 CVEs: 1 MODERATE
   surface: network
B  @opentelemetry/core@2.0.1
   1 CVEs: 1 MODERATE
   surface: network
B  @opentelemetry/core@2.3.0
   1 CVEs: 1 MODERATE
   surface: network
B  @opentelemetry/core@2.2.0
   1 CVEs: 1 MODERATE
   surface: network
B  @opentelemetry/core@1.30.1
   1 CVEs: 1 MODERATE
   surface: network
B  @ts-morph/common@0.28.1
   no known CVEs
   surface: eval · network · fs-write
B  @vercel/og@0.6.3
   no known CVEs
   surface: obfuscation · network
B  ajv@8.18.0
   no known CVEs
   surface: eval · dynamic-require · dynamic-import
B  bottleneck@2.19.5
   no known CVEs
   surface: eval · child_process
B  fsevents@2.3.3
   no known CVEs
   surface: native · dynamic-require
B  fsevents@2.3.2
   no known CVEs
   surface: native · dynamic-require
B  http-proxy-middleware@2.0.9
   1 CVEs: 1 MODERATE
   surface: network
B  jest-snapshot@29.7.0
   no known CVEs
   surface: eval · dynamic-require · fs-write
B  jwks-rsa@1.12.3
   no known CVEs
   surface: obfuscation · network
B  loader-runner@4.3.1
   no known CVEs
   surface: eval · dynamic-require · dynamic-import
B  node-fetch-native@1.6.7
   no known CVEs
   surface: obfuscation · network
B  phin@2.9.3
   1 CVEs: 1 MODERATE
   surface: network
B  posthog-js@1.274.1
   no known CVEs
   surface: obfuscation · network
B  qs@6.14.2
   1 CVEs: 1 MODERATE
   surface: dynamic-require
B  tsconfig-paths@4.2.0
   no known CVEs
   surface: child_process · dynamic-require · network
B  yoga-wasm-web@0.3.3
   no known CVEs
   surface: obfuscation · network
B  @angular-devkit/schematics-cli@17.1.2
   no known CVEs
   surface: eval · dynamic-import · bin
B  @jsforce/jsforce-node@3.10.10
   no known CVEs
   surface: child_process · network · fs-write
B  @nuxtjs/opencollective@0.3.2
   no known CVEs
   surface: child_process · network · bin
B  @oclif/core@2.15.0
   no known CVEs
   surface: dynamic-require · network · dynamic-import · fs-write
B  @prisma/fetch-engine@6.15.0
   no known CVEs
   surface: child_process · network · fs-write
B  @prisma/fetch-engine@6.16.1
   no known CVEs
   surface: child_process · network · fs-write
B  @prisma/fetch-engine@6.16.2
   no known CVEs
   surface: child_process · network · fs-write
B  @sentry/bundler-plugin-core@4.6.1
   no known CVEs
   surface: child_process · network · fs-write
B  ai@4.2.10
   1 CVEs: 1 LOW
   surface: child_process · network
B  ai@4.3.15
   1 CVEs: 1 LOW
   surface: child_process · network
B  d3-dsv@3.0.1
   no known CVEs
   surface: eval · fs-write · bin
B  es-module-lexer@1.7.0
   no known CVEs
   surface: obfuscation · dynamic-import
B  es-module-lexer@2.0.0
   no known CVEs
   surface: obfuscation · dynamic-import
B  fork-ts-checker-webpack-plugin@9.0.2
   no known CVEs
   surface: child_process · dynamic-require · fs-write
B  googleapis@84.0.0
   no known CVEs
   surface: dynamic-require · network · dynamic-import · fs-write
B  jiti@1.21.7
   no known CVEs
   surface: dynamic-require · network · dynamic-import · bin
B  nanoid@4.0.2
   1 CVEs: 1 MODERATE
   surface: bin
B  node-addon-api@7.1.1
   no known CVEs
   surface: child_process · dynamic-require · fs-write
B  node-addon-api@1.7.2
   no known CVEs
   surface: child_process · dynamic-require · fs-write
B  node-gyp-build-optional-packages@5.2.2
   no known CVEs
   surface: child_process · dynamic-require · bin
B  prebuild-install@7.1.3
   no known CVEs
   surface: dynamic-require · network · fs-write · bin
B  resolve@1.22.11
   no known CVEs
   surface: dynamic-require · network · fs-write · bin
B  ts-import@2.0.40
   no known CVEs
   surface: child_process · dynamic-require · fs-write
B  uuid@8.3.2
   1 CVEs: 1 MODERATE
   surface: bin
B  uuid@9.0.1
   1 CVEs: 1 MODERATE
   surface: bin
B  uuid@11.1.0
   1 CVEs: 1 MODERATE
   surface: bin
B  uuid@9.0.0
   1 CVEs: 1 MODERATE
   surface: bin
B  why-is-node-running@2.3.0
   no known CVEs
   surface: child_process · network · bin
B  xml-js@1.6.11
   no known CVEs
   surface: eval · fs-write · bin
B  xmlhttprequest-ssl@2.0.0
   no known CVEs
   surface: child_process · network · fs-write
B  @cspotcode/source-map-support@0.8.1
   no known CVEs
   surface: eval · dynamic-require
B  @hookform/resolvers@2.9.7
   no known CVEs
   surface: eval · network
B  @markdoc/markdoc@0.5.4
   no known CVEs
   surface: eval · network
B  @nestjs/common@10.4.20
   no known CVEs
   surface: eval · dynamic-require
B  @upstash/redis@v1.35.2
   no known CVEs
   surface: eval · network
B  @volar/typescript@2.4.27
   no known CVEs
   surface: eval · dynamic-require
B  @vue/compiler-core@3.5.26
   no known CVEs
   surface: eval · dynamic-require
B  debug@2.6.9
   no known CVEs
   surface: process.binding · network
B  es-toolkit@1.39.5
   no known CVEs
   surface: eval · network
B  faye@1.4.0
   no known CVEs
   surface: eval · network
B  husky@9.1.7
   no known CVEs
   surface: child_process · fs-write · bin
B  i18n-unused@0.13.0
   no known CVEs
   surface: child_process · fs-write · bin
B  livekit-client@2.15.6
   no known CVEs
   surface: eval · network
B  lz-string@1.4.4
   no known CVEs
   surface: obfuscation · bin
B  msgpackr@1.11.0
   no known CVEs
   surface: eval · dynamic-require
B  prisma-kysely@2.2.0
   no known CVEs
   surface: child_process · fs-write · bin
B  relay-runtime@12.0.0
   no known CVEs
   surface: eval · network
B  shelljs@0.8.5
   no known CVEs
   surface: child_process · fs-write · bin
B  source-map-support@0.5.21
   no known CVEs
   surface: eval · dynamic-require
B  swagger-ui-dist@5.17.14
   no known CVEs
   surface: eval · network
B  update-browserslist-db@1.2.2
   no known CVEs
   surface: child_process · fs-write · bin
B  update-browserslist-db@1.2.3
   no known CVEs
   surface: child_process · fs-write · bin
B  whatwg-url@13.0.0
   no known CVEs
   surface: eval · network
B  whatwg-url@14.2.0
   no known CVEs
   surface: eval · network
B  whatwg-url@12.0.1
   no known CVEs
   surface: eval · network
B  yaml-ast-parser@0.0.43
   no known CVEs
   surface: eval · dynamic-require
B  @angular-devkit/schematics@17.1.2
   no known CVEs
   surface: child_process · dynamic-require
B  @azure/identity@4.8.0
   no known CVEs
   surface: child_process · network
B  @graphql-tools/url-loader@8.0.31
   no known CVEs
   surface: dynamic-require · network · dynamic-import
B  @img/sharp-darwin-arm64@0.33.5
   no known CVEs
   surface: native
B  @img/sharp-darwin-arm64@0.34.5
   no known CVEs
   surface: native
B  @jetstreamapp/soql-parser-js@6.1.0
   no known CVEs
   surface: eval · bin
B  @modelcontextprotocol/sdk@1.26.0
   no known CVEs
   surface: child_process · network
B  @mongodb-js/saslprep@1.2.0
   no known CVEs
   surface: obfuscation
B  @msgpackr-extract/msgpackr-extract-darwin-arm64@3.0.3
   no known CVEs
   surface: native
B  @mswjs/interceptors@0.37.6
   no known CVEs
   surface: child_process · network
B  @napi-rs/simple-git@0.1.22
   no known CVEs
   surface: child_process · dynamic-require
B  @napi-rs/simple-git-darwin-arm64@0.1.22
   no known CVEs
   surface: native
B  @next/swc-darwin-arm64@16.2.3
   no known CVEs
   surface: native
B  @next/swc-darwin-arm64@15.5.15
   no known CVEs
   surface: native
B  @parcel/watcher-darwin-arm64@2.5.1
   no known CVEs
   surface: native
B  @posthog/core@1.2.4
   no known CVEs
   surface: child_process · network
B  @protobufjs/utf8@1.1.0
   1 CVEs: 1 MODERATE
   surface: none
B  @rollup/rollup-darwin-arm64@4.59.0
   no known CVEs
   surface: native
B  @rollup/rollup-darwin-arm64@4.53.2
   no known CVEs
   surface: native
B  @sentry/nextjs@10.33.0
   no known CVEs
   surface: child_process · network
B  @shikijs/engine-oniguruma@3.23.0
   no known CVEs
   surface: obfuscation
B  @shikijs/langs@3.23.0
   no known CVEs
   surface: dynamic-require · network · dynamic-import
B  @swc/core-darwin-arm64@1.15.8
   no known CVEs
   surface: native
B  @tailwindcss/oxide@4.1.15
   no known CVEs
   surface: child_process · dynamic-require
B  @tailwindcss/oxide@4.1.16
   no known CVEs
   surface: child_process · dynamic-require
B  @tailwindcss/oxide-darwin-arm64@4.1.15
   no known CVEs
   surface: native
B  @tailwindcss/oxide-darwin-arm64@4.1.16
   no known CVEs
   surface: native
B  @trigger.dev/core@4.3.2
   no known CVEs
   surface: child_process · network
B  @vercel/edge-config@0.1.1
   no known CVEs
   surface: dynamic-require · network · dynamic-import
B  @vitest/snapshot@4.0.16
   no known CVEs
   surface: eval · fs-write
B  bull@4.15.1
   no known CVEs
   surface: child_process · dynamic-require
B  busboy@1.6.0
   no known CVEs
   surface: child_process · dynamic-require
B  cjs-module-lexer@1.3.1
   no known CVEs
   surface: obfuscation
B  d3-scale-chromatic@3.1.0
   no known CVEs
   surface: obfuscation
B  decimal.js@10.4.3
   no known CVEs
   surface: obfuscation
B  entities@7.0.0
   no known CVEs
   surface: obfuscation
B  exsolve@1.0.7
   no known CVEs
   surface: child_process · network
B  fb-watchman@2.0.1
   no known CVEs
   surface: child_process · network
B  fetch-retry@6.0.0
   no known CVEs
   surface: child_process · network
B  http@0.0.1-security
   1 CVEs: 1 unknown-severity
   surface: none
B  ip-address@9.0.5
   1 CVEs: 1 MODERATE
   surface: none
B  ip-address@10.1.0
   1 CVEs: 1 MODERATE
   surface: none
B  jest-cli@29.7.0
   no known CVEs
   surface: process.binding · bin
B  jest-haste-map@29.7.0
   no known CVEs
   surface: child_process · dynamic-require
B  jest-worker@29.7.0
   no known CVEs
   surface: child_process · dynamic-require
B  jest-worker@27.5.1
   no known CVEs
   surface: child_process · dynamic-require
B  lightningcss-darwin-arm64@1.30.2
   no known CVEs
   surface: native
B  linebreak@1.1.0
   no known CVEs
   surface: obfuscation
B  lodash@4.18.1
   no known CVEs
   surface: process.binding · fs-write
B  lodash-es@4.18.1
   no known CVEs
   surface: process.binding · fs-write
B  magicast@0.5.2
   no known CVEs
   surface: eval · fs-write
B  moment-timezone@0.5.43
   no known CVEs
   surface: obfuscation
B  mongodb@6.16.0
   no known CVEs
   surface: child_process · network
B  mz@2.7.0
   no known CVEs
   surface: child_process · network
B  nostr-wasm@0.1.0
   no known CVEs
   surface: obfuscation
B  stripe@9.16.0
   no known CVEs
   surface: child_process · network
B  stripe@15.4.0
   no known CVEs
   surface: child_process · network
B  sync-fetch@0.6.0-2
   no known CVEs
   surface: child_process · network
B  tedious@18.6.2
   no known CVEs
   surface: child_process · network
B  uglify-js@3.17.4
   no known CVEs
   surface: eval · bin
B  xml2js@0.4.23
   1 CVEs: 1 MODERATE
   surface: none
B  yaml@1.10.2
   1 CVEs: 1 MODERATE
   surface: none
A  @inquirer/external-editor@1.0.3
   no known CVEs
   surface: child_process · fs-write
A  @prisma/get-platform@5.22.0
   no known CVEs
   surface: child_process · fs-write
A  @rushstack/node-core-library@5.19.1
   no known CVEs
   surface: child_process · fs-write
A  @snyk/protect@1.1295.4
   no known CVEs
   surface: network · fs-write · bin
A  cardinal@2.1.1
   no known CVEs
   surface: dynamic-require · fs-write · bin
A  concurrently@9.1.2
   no known CVEs
   surface: child_process · bin
A  detect-libc@1.0.3
   no known CVEs
   surface: child_process · bin
A  execa@9.3.0
   no known CVEs
   surface: child_process · fs-write
A  execa@8.0.1
   no known CVEs
   surface: child_process · fs-write
A  external-editor@3.1.0
   no known CVEs
   surface: child_process · fs-write
A  jiti@2.6.1
   no known CVEs
   surface: dynamic-require · dynamic-import · bin
A  katex@0.16.45
   no known CVEs
   surface: network · fs-write · bin
A  libphonenumber-js@1.12.38
   no known CVEs
   surface: child_process · fs-write
A  micro@10.0.1
   no known CVEs
   surface: network · dynamic-import · bin
A  opener@1.5.2
   no known CVEs
   surface: child_process · bin
A  pagefind@1.5.2
   no known CVEs
   surface: child_process · bin
A  pidtree@0.5.0
   no known CVEs
   surface: child_process · bin
A  pidtree@0.3.1
   no known CVEs
   surface: child_process · bin
A  tree-kill@1.2.2
   no known CVEs
   surface: child_process · bin
A  vscode-languageserver@9.0.1
   no known CVEs
   surface: child_process · bin
A  @biomejs/wasm-nodejs@2.3.7
   no known CVEs
   surface: eval
A  @chevrotain/utils@10.5.0
   no known CVEs
   surface: eval
A  @mdx-js/mdx@3.1.1
   no known CVEs
   surface: eval
A  @prisma/schema-engine-wasm@6.15.0-5.85179d7826409ee107a6ba334b5e305ae3fba9fb
   no known CVEs
   surface: eval
A  @prisma/schema-engine-wasm@6.16.0-7.1c57fdcd7e44b29b9313256c76699e91c3ac3c43
   no known CVEs
   surface: eval
A  @protobufjs/inquire@1.1.0
   no known CVEs
   surface: eval
A  @sentry/core@8.55.0
   no known CVEs
   surface: dynamic-require · network
A  @sentry/core@10.33.0
   no known CVEs
   surface: dynamic-require · network
A  @sentry/core@9.46.0
   no known CVEs
   surface: dynamic-require · network
A  @sinonjs/commons@3.0.1
   no known CVEs
   surface: eval
A  @vue/compiler-dom@3.5.26
   no known CVEs
   surface: eval
A  @vue/compiler-vue2@2.7.16
   no known CVEs
   surface: eval
A  bluebird@3.7.2
   no known CVEs
   surface: eval
A  builtin-modules@3.3.0
   no known CVEs
   surface: process.binding
A  depd@2.0.0
   no known CVEs
   surface: eval
A  depd@1.1.2
   no known CVEs
   surface: eval
A  domexception@4.0.0
   no known CVEs
   surface: eval
A  eslint-scope@5.1.1
   no known CVEs
   surface: eval
A  express@5.2.1
   no known CVEs
   surface: dynamic-require · network
A  express@5.1.0
   no known CVEs
   surface: dynamic-require · network
A  express@4.21.2
   no known CVEs
   surface: dynamic-require · network
A  fflate@0.4.8
   no known CVEs
   surface: eval
A  fn.name@1.1.0
   no known CVEs
   surface: eval
A  fs-minipass@2.1.0
   no known CVEs
   surface: process.binding
A  globalthis@1.0.4
   no known CVEs
   surface: eval
A  gray-matter@4.0.3
   no known CVEs
   surface: eval
A  http-call@5.3.0
   no known CVEs
   surface: dynamic-require · network
A  is-core-module@2.16.1
   no known CVEs
   surface: dynamic-require · network
A  istanbul-lib-instrument@5.1.0
   no known CVEs
   surface: eval
A  istanbul-lib-instrument@6.0.2
   no known CVEs
   surface: eval
A  lint-staged@12.5.0
   no known CVEs
   surface: dynamic-import · fs-write · bin
A  lodash.merge@4.6.2
   no known CVEs
   surface: process.binding
A  mysql2@3.14.1
   no known CVEs
   surface: dynamic-require · network
A  node-forge@1.4.0
   no known CVEs
   surface: eval
A  property-expr@2.0.5
   no known CVEs
   surface: eval
A  rate-limiter-flexible@4.0.1
   no known CVEs
   surface: eval
A  react-phone-input-2@2.15.1
   no known CVEs
   surface: eval
A  recharts@3.0.2
   no known CVEs
   surface: eval
A  safer-buffer@2.1.2
   no known CVEs
   surface: process.binding
A  setimmediate@1.0.5
   no known CVEs
   surface: eval
A  source-map-js@1.2.1
   no known CVEs
   surface: eval
A  source-map-support@0.5.13
   no known CVEs
   surface: eval
A  stacktrace-gps@3.1.2
   no known CVEs
   surface: eval
A  stacktrace-js@2.0.2
   no known CVEs
   surface: eval
A  styled-jsx@5.1.6
   no known CVEs
   surface: dynamic-require · network
A  tapable@2.2.1
   no known CVEs
   surface: eval
A  tapable@2.3.2
   no known CVEs
   surface: eval
A  terser-webpack-plugin@5.4.0
   no known CVEs
   surface: eval
A  tmpl@1.0.5
   no known CVEs
   surface: eval
A  tsconfig-paths-webpack-plugin@4.1.0
   no known CVEs
   surface: eval
A  yoga-layout-prebuilt@1.10.0
   no known CVEs
   surface: eval
A  zod-prisma-types@3.2.4
   no known CVEs
   surface: dynamic-import · fs-write · bin
A  @ai-sdk/provider-utils@2.2.3
   1 CVEs: 1 LOW
   surface: network
A  @ai-sdk/provider-utils@2.2.8
   1 CVEs: 1 LOW
   surface: network
A  @angular-devkit/core@17.1.2
   no known CVEs
   surface: network · fs-write
A  @aws-sdk/credential-provider-process@3.816.0
   no known CVEs
   surface: child_process
A  @azure/msal-browser@4.7.0
   no known CVEs
   surface: network · dynamic-import
A  @changesets/apply-release-plan@7.0.12
   no known CVEs
   surface: dynamic-require · fs-write
A  @datocms/cma-client-node@4.0.1
   no known CVEs
   surface: network · fs-write
A  @graphql-tools/code-file-loader@8.1.20
   no known CVEs
   surface: dynamic-require · dynamic-import
A  @graphql-tools/git-loader@8.0.24
   no known CVEs
   surface: child_process
A  @graphql-tools/load@8.0.19
   no known CVEs
   surface: dynamic-require · dynamic-import
A  @graphql-tools/prisma-loader@8.0.17
   no known CVEs
   surface: network · fs-write
A  @istanbuljs/load-nyc-config@1.1.0
   no known CVEs
   surface: dynamic-require · dynamic-import
A  @jest/core@29.7.0
   no known CVEs
   surface: dynamic-require · fs-write
A  @oclif/plugin-plugins@2.3.0
   no known CVEs
   surface: child_process
A  @oclif/plugin-warn-if-update-available@2.0.24
   no known CVEs
   surface: child_process
A  @opentelemetry/resources@2.0.1
   no known CVEs
   surface: child_process
A  @opentelemetry/resources@2.3.0
   no known CVEs
   surface: child_process
A  @opentelemetry/resources@1.30.1
   no known CVEs
   surface: child_process
A  @prisma/generator-helper@5.22.0
   no known CVEs
   surface: child_process
A  @prisma/generator-helper@6.15.0
   no known CVEs
   surface: child_process
A  @prisma/generator-helper@6.16.2
   no known CVEs
   surface: child_process
A  @shuding/opentype.js@1.4.0-beta.0
   no known CVEs
   surface: network · bin
A  @trpc/server@11.0.0-next-beta.222+3c3fb2a38
   no known CVEs
   surface: network · fs-write
A  @typescript/vfs@1.6.4
   no known CVEs
   surface: dynamic-require · fs-write
A  @vitest/ui@4.0.16
   no known CVEs
   surface: network · fs-write
A  @vue/language-core@2.2.0
   no known CVEs
   surface: dynamic-require · fs-write
A  address@1.2.0
   no known CVEs
   surface: child_process
A  babel-plugin-istanbul@6.1.1
   no known CVEs
   surface: child_process
A  browserslist@4.28.1
   no known CVEs
   surface: dynamic-require · bin
A  browserslist@4.28.2
   no known CVEs
   surface: dynamic-require · bin
A  bson@6.10.3
   no known CVEs
   surface: child_process
A  commander@4.1.1
   no known CVEs
   surface: child_process
A  commander@7.2.0
   no known CVEs
   surface: child_process
A  commander@9.5.0
   no known CVEs
   surface: child_process
A  commander@2.20.3
   no known CVEs
   surface: child_process
A  commander@11.1.0
   no known CVEs
   surface: child_process
A  commander@13.1.0
   no known CVEs
   surface: child_process
A  commander@12.1.0
   no known CVEs
   surface: child_process
A  commander@8.3.0
   no known CVEs
   surface: child_process
A  commander@14.0.2
   no known CVEs
   surface: child_process
A  commander@9.1.0
   no known CVEs
   surface: child_process
A  cron@3.1.7
   no known CVEs
   surface: child_process
A  cross-spawn@7.0.6
   no known CVEs
   surface: child_process
A  cross-spawn@6.0.6
   no known CVEs
   surface: child_process
A  default-browser@5.2.1
   no known CVEs
   surface: child_process
A  default-browser-id@5.0.0
   no known CVEs
   surface: child_process
A  detect-libc@2.0.4
   no known CVEs
   surface: child_process
A  detect-libc@2.1.2
   no known CVEs
   surface: child_process
A  detect-port@1.3.0
   no known CVEs
   surface: network · bin
A  env-cmd@10.1.0
   no known CVEs
   surface: dynamic-require · bin
A  execa@5.1.1
   no known CVEs
   surface: child_process
A  exit@0.1.2
   no known CVEs
   surface: child_process
A  fetch@1.1.0
   no known CVEs
   surface: network · fs-write
A  figlet@1.9.4
   no known CVEs
   surface: network · bin
A  foreground-child@3.3.1
   no known CVEs
   surface: child_process
A  foreground-child@2.0.0
   no known CVEs
   surface: child_process
A  git-last-commit@1.0.1
   no known CVEs
   surface: child_process
A  google-auth-library@9.15.0
   no known CVEs
   surface: child_process
A  google-auth-library@7.14.1
   no known CVEs
   surface: child_process
A  import-local@3.1.0
   no known CVEs
   surface: dynamic-require · bin
A  inline-style-prefixer@7.0.1
   no known CVEs
   surface: dynamic-require · fs-write
A  istanbul-reports@3.1.7
   no known CVEs
   surface: dynamic-require · fs-write
A  istanbul-reports@3.2.0
   no known CVEs
   surface: dynamic-require · fs-write
A  jest-junit@16.0.0
   no known CVEs
   surface: dynamic-require · fs-write
A  jest-util@29.7.0
   no known CVEs
   surface: dynamic-require · dynamic-import
A  jimp@0.16.1
   no known CVEs
   surface: network · fs-write
A  jsondiffpatch@0.7.2
   no known CVEs
   surface: network · bin
A  memorystream@0.3.1
   no known CVEs
   surface: network · fs-write
A  mixpanel@0.18.1
   no known CVEs
   surface: network · dynamic-import
A  mlly@1.8.0
   no known CVEs
   surface: dynamic-require · dynamic-import
A  mlly@1.8.2
   no known CVEs
   surface: dynamic-require · dynamic-import
A  mqtt@4.3.7
   no known CVEs
   surface: network · bin
A  next-i18next@15.4.2
   no known CVEs
   surface: dynamic-require · dynamic-import
A  node-machine-id@1.1.12
   no known CVEs
   surface: child_process
A  npm-run-all@4.1.5
   no known CVEs
   surface: dynamic-require · bin
A  open@10.2.0
   no known CVEs
   surface: child_process
A  open@8.4.0
   no known CVEs
   surface: child_process
A  postcss-load-config@5.1.0
   no known CVEs
   surface: dynamic-require · dynamic-import
A  process-wrapper@1.0.0
   no known CVEs
   surface: child_process
A  retell-sdk@4.41.0
   no known CVEs
   surface: network · dynamic-import
A  run-applescript@7.0.0
   no known CVEs
   surface: child_process
A  system-architecture@0.1.0
   no known CVEs
   surface: child_process
A  term-size@2.2.1
   no known CVEs
   surface: child_process
A  tinyexec@0.3.2
   no known CVEs
   surface: child_process
A  tinyexec@1.0.2
   no known CVEs
   surface: child_process
A  tinyexec@1.0.1
   no known CVEs
   surface: child_process
A  tldts@6.1.86
   no known CVEs
   surface: network · bin
A  tmp-promise@3.0.3
   no known CVEs
   surface: child_process
A  ts-jest@29.1.4
   no known CVEs
   surface: dynamic-require · bin
A  ts-loader@9.5.1
   no known CVEs
   surface: dynamic-require · fs-write
A  v8-compile-cache-lib@3.0.1
   no known CVEs
   surface: dynamic-require · fs-write
A  web-push@3.6.7
   no known CVEs
   surface: network · bin
A  winston@3.17.0
   no known CVEs
   surface: network · fs-write
A  @babel/core@7.28.5
   1 CVEs: 1 LOW
   surface: dynamic-import
A  @babel/core@7.26.10
   1 CVEs: 1 LOW
   surface: dynamic-import
A  @babel/parser@7.29.2
   no known CVEs
   surface: dynamic-import · bin
A  @babel/parser@7.28.5
   no known CVEs
   surface: dynamic-import · bin
A  @grpc/proto-loader@0.7.13
   no known CVEs
   surface: fs-write · bin
A  @microsoft/api-extractor@7.55.2
   no known CVEs
   surface: fs-write · bin
A  @sentry/profiling-node@9.46.0
   no known CVEs
   surface: fs-write · bin
A  @tailwindcss/cli@4.1.16
   no known CVEs
   surface: fs-write · bin
A  c12@3.1.0
   no known CVEs
   surface: dynamic-import · fs-write
A  create-jest@29.7.0
   no known CVEs
   surface: fs-write · bin
A  handlebars@4.7.9
   no known CVEs
   surface: fs-write · bin
A  json5@2.2.3
   no known CVEs
   surface: fs-write · bin
A  jsonrepair@3.13.1
   no known CVEs
   surface: fs-write · bin
A  mime@1.6.0
   no known CVEs
   surface: fs-write · bin
A  node-webvtt@1.9.4
   no known CVEs
   surface: fs-write · bin
A  nypm@0.5.4
   no known CVEs
   surface: fs-write · bin
A  nypm@0.6.1
   no known CVEs
   surface: fs-write · bin
A  postcss-cli@11.0.1
   no known CVEs
   surface: dynamic-import · bin
A  qrcode@1.5.1
   no known CVEs
   surface: fs-write · bin
A  rc@1.2.8
   no known CVEs
   surface: fs-write · bin
A  rimraf@3.0.2
   no known CVEs
   surface: fs-write · bin
A  rimraf@4.4.1
   no known CVEs
   surface: fs-write · bin
A  srt-parser-2@1.2.3
   no known CVEs
   surface: fs-write · bin
A  yaml@2.8.3
   no known CVEs
   surface: dynamic-import · bin
A  @asamuzakjp/css-color@3.2.0
   no known CVEs
   surface: network
A  @aws-sdk/client-cognito-identity@3.817.0
   no known CVEs
   surface: network
A  @aws-sdk/client-dynamodb@3.817.0
   no known CVEs
   surface: network
A  @aws-sdk/nested-clients@3.817.0
   no known CVEs
   surface: network
A  @azure/core-rest-pipeline@1.19.1
   no known CVEs
   surface: network
A  @azure/msal-node@3.3.0
   no known CVEs
   surface: network
A  @boxyhq/error-code-mnemonic@0.1.1
   no known CVEs
   surface: network
A  @bundled-es-modules/tough-cookie@0.1.6
   no known CVEs
   surface: network
A  @changesets/get-github-info@0.6.0
   no known CVEs
   surface: network
A  @changesets/write@0.4.0
   no known CVEs
   surface: dynamic-require
A  @colors/colors@1.5.0
   no known CVEs
   surface: dynamic-require
A  @colors/colors@1.6.0
   no known CVEs
   surface: dynamic-require
A  @daily-co/daily-js@0.83.1
   no known CVEs
   surface: network
A  @datocms/cma-client@4.0.2
   no known CVEs
   surface: network
A  @datocms/rest-client-utils@4.0.2
   no known CVEs
   surface: network
A  @electric-sql/client@1.0.14
   no known CVEs
   surface: network
A  @ewsjs/xhr@3.1.3
   no known CVEs
   surface: network
A  @faker-js/faker@8.4.1
   no known CVEs
   surface: network
A  @faker-js/faker@9.2.0
   no known CVEs
   surface: network
A  @formbricks/api@3.0.0
   no known CVEs
   surface: network
A  @getalby/lightning-tools@5.1.2
   no known CVEs
   surface: network
A  @getalby/sdk@4.0.0
   no known CVEs
   surface: network
A  @gitbeaker/rest@39.34.3
   no known CVEs
   surface: network
A  @graphql-tools/apollo-engine-loader@8.0.20
   no known CVEs
   surface: network
A  @graphql-tools/executor@1.4.7
   no known CVEs
   surface: network
A  @graphql-tools/executor-graphql-ws@2.0.5
   no known CVEs
   surface: network
A  @graphql-tools/executor-http@1.3.3
   no known CVEs
   surface: network
A  @graphql-tools/executor-legacy-ws@1.1.17
   no known CVEs
   surface: network
A  @libsql/hrana-client@0.4.4
   no known CVEs
   surface: network
A  @libsql/isomorphic-fetch@0.1.12
   no known CVEs
   surface: network
A  @libsql/isomorphic-ws@0.1.5
   no known CVEs
   surface: network
A  @lingo.dev/_locales@0.3.1
   no known CVEs
   surface: network
A  @lingo.dev/_sdk@0.13.4
   no known CVEs
   surface: network
A  @mermaid-js/parser@1.1.0
   no known CVEs
   surface: network
A  @microsoft/fetch-event-source@2.0.1
   no known CVEs
   surface: network
A  @nestjs/platform-express@10.4.20
   no known CVEs
   surface: network
A  @nestjs/schematics@10.1.1
   no known CVEs
   surface: dynamic-require
A  @nestjs/swagger@7.4.2
   no known CVEs
   surface: network
A  @noble/hashes@1.3.1
   no known CVEs
   surface: network
A  @noble/hashes@1.3.2
   no known CVEs
   surface: network
A  @npmcli/agent@2.2.2
   no known CVEs
   surface: network
A  @octokit/request@9.2.4
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation@0.203.0
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation@0.209.0
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation@0.208.0
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation-amqplib@0.55.0
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation-amqplib@0.46.1
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation-fetch@0.203.0
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation-hapi@0.55.0
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation-http@0.208.0
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation-http@0.57.2
   no known CVEs
   surface: network
A  @opentelemetry/instrumentation-mysql2@0.55.0
   no known CVEs
   surface: network
A  @opentelemetry/otlp-exporter-base@0.57.1
   no known CVEs
   surface: network
A  @opentelemetry/otlp-exporter-base@0.203.0
   no known CVEs
   surface: network
A  @opentelemetry/semantic-conventions@1.36.0
   no known CVEs
   surface: network
A  @opentelemetry/semantic-conventions@1.38.0
   no known CVEs
   surface: network
A  @opentelemetry/semantic-conventions@1.28.0
   no known CVEs
   surface: network
A  @opentelemetry/semantic-conventions@1.29.0
   no known CVEs
   surface: network
A  @posthog/core@1.6.0
   no known CVEs
   surface: network
A  @prisma/extension-accelerate@1.3.0
   no known CVEs
   surface: network
A  @prisma/prisma-schema-wasm@5.22.0-44.605197351a3c8bdd595af2d2a9bc3025bca48ea2
   no known CVEs
   surface: dynamic-require
A  @prisma/prisma-schema-wasm@6.15.0-5.85179d7826409ee107a6ba334b5e305ae3fba9fb
   no known CVEs
   surface: dynamic-require
A  @prisma/prisma-schema-wasm@6.16.0-7.1c57fdcd7e44b29b9313256c76699e91c3ac3c43
   no known CVEs
   surface: dynamic-require
A  @protobufjs/fetch@1.1.0
   no known CVEs
   surface: network
A  @redis/client@1.6.0
   no known CVEs
   surface: network
A  @reduxjs/toolkit@2.8.2
   no known CVEs
   surface: network
A  @resvg/resvg-wasm@2.4.0
   no known CVEs
   surface: network
A  @rollup/plugin-commonjs@28.0.1
   no known CVEs
   surface: dynamic-require
A  @s2-dev/streamstore@0.17.6
   no known CVEs
   surface: network
A  @s2-dev/streamstore@0.17.3
   no known CVEs
   surface: network
A  @sentry-internal/browser-utils@10.33.0
   no known CVEs
   surface: network
A  @sentry-internal/browser-utils@8.55.0
   no known CVEs
   surface: network
A  @sentry-internal/replay@8.55.0
   no known CVEs
   surface: network
A  @sentry-internal/replay@10.33.0
   no known CVEs
   surface: network
A  @sentry/browser@8.55.0
   no known CVEs
   surface: network
A  @sentry/browser@10.33.0
   no known CVEs
   surface: network
A  @sentry/nestjs@9.46.0
   no known CVEs
   surface: network
A  @sentry/node@10.33.0
   no known CVEs
   surface: network
A  @sentry/opentelemetry@10.33.0
   no known CVEs
   surface: network
A  @sentry/opentelemetry@9.46.0
   no known CVEs
   surface: network
A  @sentry/vercel-edge@10.33.0
   no known CVEs
   surface: network
A  @smithy/core@3.8.0
   no known CVEs
   surface: network
A  @smithy/credential-provider-imds@4.0.7
   no known CVEs
   surface: network
A  @smithy/fetch-http-handler@5.1.1
   no known CVEs
   surface: network
A  @smithy/node-http-handler@4.1.1
   no known CVEs
   surface: network
A  @smithy/types@4.3.2
   no known CVEs
   surface: network
A  @snaplet/copycat@4.1.0
   no known CVEs
   surface: network
A  @stripe/stripe-js@1.35.0
   no known CVEs
   surface: dynamic-require
A  @tanstack/query-core@5.17.19
   no known CVEs
   surface: network
A  @tanstack/react-query@5.17.19
   no known CVEs
   surface: network
A  @testing-library/react-hooks@8.0.1
   no known CVEs
   surface: dynamic-require
A  @trigger.dev/build@4.3.2
   no known CVEs
   surface: network
A  @trigger.dev/sdk@4.3.2
   no known CVEs
   surface: network
A  @trpc/client@11.0.0-next-beta.222+3c3fb2a38
   no known CVEs
   surface: network
A  @trpc/next@11.0.0-next-beta.222+3c3fb2a38
   no known CVEs
   surface: network
A  @trpc/react-query@11.0.0-next-beta.222+3c3fb2a38
   no known CVEs
   surface: network
A  @types/ws@8.18.1
   no known CVEs
   surface: network
A  @whatwg-node/fetch@0.10.5
   no known CVEs
   surface: dynamic-require
A  @whatwg-node/node-fetch@0.7.17
   no known CVEs
   surface: network
A  agent-base@6.0.2
   no known CVEs
   surface: network
A  agent-base@7.1.4
   no known CVEs
   surface: network
A  agentkeepalive@4.6.0
   no known CVEs
   surface: network
A  any-promise@1.3.0
   no known CVEs
   surface: dynamic-require
A  app-root-path@3.1.0
   no known CVEs
   surface: dynamic-require
A  async-mqtt@2.6.3
   no known CVEs
   surface: network
A  biskviit@1.0.1
   no known CVEs
   surface: network
A  bitbucket@2.12.0
   no known CVEs
   surface: network
A  botid@1.5.7
   no known CVEs
   surface: network
A  class-validator@0.14.3
   no known CVEs
   surface: network
A  connect@3.7.0
   no known CVEs
   surface: network
A  cross-fetch@3.2.0
   no known CVEs
   surface: network
A  cross-fetch@3.1.5
   no known CVEs
   surface: network
A  cssnano@7.1.2
   no known CVEs
   surface: dynamic-require
A  d3-fetch@3.0.1
   no known CVEs
   surface: network
A  deepmerge@3.3.0
   no known CVEs
   surface: dynamic-require
A  domutils@3.2.2
   no known CVEs
   surface: network
A  duplexify@4.1.2
   no known CVEs
   surface: network
A  encoding@0.1.12
   no known CVEs
   surface: dynamic-require
A  engine.io-client@6.5.4
   no known CVEs
   surface: network
A  engine.io-parser@5.2.3
   no known CVEs
   surface: network
A  eventsource@3.0.7
   no known CVEs
   surface: network
A  evt@2.5.9
   no known CVEs
   surface: network
A  ews-javascript-api@0.11.0
   no known CVEs
   surface: network
A  express-rate-limit@8.2.2
   no known CVEs
   surface: network
A  fast-check@3.23.2
   no known CVEs
   surface: network
A  fast-json-stable-stringify@2.1.0
   no known CVEs
   surface: dynamic-require
A  fastest-stable-stringify@2.0.2
   no known CVEs
   surface: dynamic-require
A  faye-websocket@0.11.4
   no known CVEs
   surface: network
A  fbjs@3.0.5
   no known CVEs
   surface: network
A  find-root@1.1.0
   no known CVEs
   surface: dynamic-require
A  follow-redirects@1.16.0
   no known CVEs
   surface: network
A  format@0.2.2
   no known CVEs
   surface: dynamic-require
A  formidable@2.1.3
   no known CVEs
   surface: dynamic-require
A  fs-monkey@1.0.5
   no known CVEs
   surface: dynamic-require
A  gaxios@4.3.3
   no known CVEs
   surface: network
A  gaxios@6.1.1
   no known CVEs
   surface: network
A  get-port@5.1.1
   no known CVEs
   surface: network
A  graphql-request@6.1.0
   no known CVEs
   surface: network
A  graphql-tag@2.12.6
   no known CVEs
   surface: dynamic-require
A  graphql-ws@6.0.4
   no known CVEs
   surface: network
A  helmet@7.1.0
   no known CVEs
   surface: network
A  hosted-git-info@2.8.9
   no known CVEs
   surface: network
A  hosted-git-info@4.1.0
   no known CVEs
   surface: network
A  http-cookie-agent@5.0.4
   no known CVEs
   surface: network
A  http-proxy@1.18.1
   no known CVEs
   surface: network
A  http-proxy-agent@7.0.2
   no known CVEs
   surface: network
A  http-proxy-agent@4.0.1
   no known CVEs
   surface: network
A  http-proxy-agent@5.0.0
   no known CVEs
   surface: network
A  https-proxy-agent@5.0.1
   no known CVEs
   surface: network
A  https-proxy-agent@7.0.6
   no known CVEs
   surface: network
A  https-proxy-agent@5.0.0
   no known CVEs
   surface: network
A  import-fresh@3.3.0
   no known CVEs
   surface: dynamic-require
A  ink@3.2.0
   no known CVEs
   surface: network
A  ink@4.2.0
   no known CVEs
   surface: network
A  ioredis@5.3.2
   no known CVEs
   surface: network
A  iso-639-3@3.0.1
   no known CVEs
   surface: network
A  isomorphic-ws@5.0.0
   no known CVEs
   surface: network
A  jest-config@29.7.0
   no known CVEs
   surface: dynamic-require
A  jest-pnp-resolver@1.2.3
   no known CVEs
   surface: dynamic-require
A  jest-resolve@29.7.0
   no known CVEs
   surface: dynamic-require
A  jest-runner@29.7.0
   no known CVEs
   surface: dynamic-require
A  jest-runtime@29.7.0
   no known CVEs
   surface: dynamic-require
A  jose@4.15.9
   no known CVEs
   surface: network
A  jose@5.10.0
   no known CVEs
   surface: network
A  lightningcss@1.30.2
   no known CVEs
   surface: dynamic-require
A  listr2@8.3.2
   no known CVEs
   surface: network
A  lru-cache@9.0.3
   no known CVEs
   surface: network
A  lru-cache@10.4.3
   no known CVEs
   surface: network
A  lru-cache@7.18.3
   no known CVEs
   surface: network
A  lru-cache@11.2.2
   no known CVEs
   surface: network
A  mailhog@4.16.0
   no known CVEs
   surface: network
A  make-fetch-happen@10.2.1
   no known CVEs
   surface: network
A  make-fetch-happen@9.1.0
   no known CVEs
   surface: network
A  make-fetch-happen@13.0.1
   no known CVEs
   surface: network
A  methods@1.1.2
   no known CVEs
   surface: network
A  micromark-extension-gfm-autolink-literal@2.1.0
   no known CVEs
   surface: network
A  minipass-fetch@2.1.2
   no known CVEs
   surface: network
A  minipass-fetch@1.4.1
   no known CVEs
   surface: network
A  minipass-fetch@3.0.5
   no known CVEs
   surface: network
A  module-alias@2.2.2
   no known CVEs
   surface: dynamic-require
A  mqtt-packet@6.10.0
   no known CVEs
   surface: network
A  napi-build-utils@2.0.0
   no known CVEs
   surface: dynamic-require
A  next-axiom@0.17.0
   no known CVEs
   surface: network
A  node-abort-controller@3.0.1
   no known CVEs
   surface: network
A  node-fetch@2.7.0
   no known CVEs
   surface: network
A  node-fetch@2.6.7
   no known CVEs
   surface: network
A  node-fetch@3.3.2
   no known CVEs
   surface: network
A  node-mocks-http@1.16.2
   no known CVEs
   surface: network
A  nostr-tools@2.9.4
   no known CVEs
   surface: network
A  npmlog@6.0.2
   no known CVEs
   surface: network
A  oauth@0.9.15
   no known CVEs
   surface: network
A  openid-client@5.4.0
   no known CVEs
   surface: network
A  partysocket@1.1.6
   no known CVEs
   surface: network
A  passport@0.7.0
   no known CVEs
   surface: network
A  pg@8.16.0
   no known CVEs
   surface: network
A  polka@0.5.2
   no known CVEs
   surface: network
A  posthog-node@5.14.0
   no known CVEs
   surface: network
A  proc-log@4.2.0
   no known CVEs
   surface: network
A  prom-client@15.1.3
   no known CVEs
   surface: network
A  prop-types@15.8.1
   no known CVEs
   surface: dynamic-require
A  psl@1.15.0
   no known CVEs
   surface: network
A  react-inlinesvg@4.1.3
   no known CVEs
   surface: network
A  rechoir@0.6.2
   no known CVEs
   surface: dynamic-require
A  require-directory@2.1.1
   no known CVEs
   surface: dynamic-require
A  require-in-the-middle@7.3.0
   no known CVEs
   surface: dynamic-require
A  require-in-the-middle@8.0.1
   no known CVEs
   surface: dynamic-require
A  requires-port@1.0.0
   no known CVEs
   surface: network
A  rest-facade@1.16.3
   no known CVEs
   surface: network
A  retry@0.13.1
   no known CVEs
   surface: network
A  router@2.2.0
   no known CVEs
   surface: network
A  rxjs@7.8.2
   no known CVEs
   surface: network
A  rxjs@7.8.1
   no known CVEs
   surface: network
A  sanitize-html@2.17.0
   no known CVEs
   surface: network
A  satori@0.10.9
   no known CVEs
   surface: network
A  shiki@3.23.0
   no known CVEs
   surface: network
A  simple-get@4.0.1
   no known CVEs
   surface: network
A  sirv@3.0.2
   no known CVEs
   surface: network
A  socket.io@4.7.4
   no known CVEs
   surface: network
A  socket.io-adapter@2.5.5
   no known CVEs
   surface: network
A  socket.io-client@4.7.5
   no known CVEs
   surface: network
A  socks@2.8.3
   no known CVEs
   surface: network
A  socks-proxy-agent@7.0.0
   no known CVEs
   surface: network
A  socks-proxy-agent@6.2.1
   no known CVEs
   surface: network
A  socks-proxy-agent@8.0.4
   no known CVEs
   surface: network
A  source-map@0.7.4
   no known CVEs
   surface: network
A  source-map@0.7.6
   no known CVEs
   surface: network
A  stoppable@1.1.0
   no known CVEs
   surface: network
A  superagent@8.1.2
   no known CVEs
   surface: network
A  superagent@5.3.1
   no known CVEs
   surface: network
A  supertest@6.3.4
   no known CVEs
   surface: network
A  svix@0.85.1
   no known CVEs
   surface: network
A  svix@0.64.2
   no known CVEs
   surface: network
A  svix-fetch@3.0.0
   no known CVEs
   surface: network
A  swr@2.3.6
   no known CVEs
   surface: network
A  tldts-core@6.1.86
   no known CVEs
   surface: network
A  tough-cookie@5.1.2
   no known CVEs
   surface: network
A  tsdav@2.0.3
   no known CVEs
   surface: network
A  tunnel@0.0.6
   no known CVEs
   surface: network
A  tunnel-agent@0.6.0
   no known CVEs
   surface: network
A  uri-js@4.4.1
   no known CVEs
   surface: network
A  url-parse@1.5.10
   no known CVEs
   surface: network
A  urlpattern-polyfill@10.0.0
   no known CVEs
   surface: network
A  validator@13.15.22
   no known CVEs
   surface: network
A  vscode-jsonrpc@8.2.0
   no known CVEs
   surface: network
A  vscode-uri@3.1.0
   no known CVEs
   surface: network
A  webrtc-adapter@9.0.3
   no known CVEs
   surface: network
A  websocket-extensions@0.1.4
   no known CVEs
   surface: network
A  whatwg-fetch@3.6.20
   no known CVEs
   surface: network
A  whatwg-url@5.0.0
   no known CVEs
   surface: network
A  xml@1.0.1
   no known CVEs
   surface: network
A  yargs@17.7.2
   no known CVEs
   surface: dynamic-require
A  yargs@15.4.1
   no known CVEs
   surface: dynamic-require
A  yargs@16.2.0
   no known CVEs
   surface: dynamic-require
A  yargs-parser@20.2.9
   no known CVEs
   surface: dynamic-require
A  yargs-parser@21.1.1
   no known CVEs
   surface: dynamic-require
A  yargs-parser@18.1.3
   no known CVEs
   surface: dynamic-require
A  zod@3.25.76
   no known CVEs
   surface: network
A  zod@4.1.8
   no known CVEs
   surface: network
A  @adobe/css-tools@4.3.2
   no known CVEs
   surface: dynamic-import
A  @apm-js-collab/tracing-hooks@0.3.1
   no known CVEs
   surface: fs-write
A  @aws-sdk/token-providers@3.817.0
   no known CVEs
   surface: fs-write
A  @biomejs/biome@2.3.10
   no known CVEs
   surface: bin
A  @gitbeaker/core@39.34.3
   no known CVEs
   surface: dynamic-import
A  @googleapis/calendar@9.7.9
   no known CVEs
   surface: dynamic-import
A  @iconify/utils@3.1.0
   no known CVEs
   surface: dynamic-import
A  @jest/test-sequencer@29.7.0
   no known CVEs
   surface: fs-write
A  @jest/transform@29.7.0
   no known CVEs
   surface: fs-write
A  @jimp/core@0.16.1
   no known CVEs
   surface: fs-write
A  @microsoft/tsdoc-config@0.18.0
   no known CVEs
   surface: fs-write
A  @npmcli/fs@1.1.1
   no known CVEs
   surface: fs-write
A  @npmcli/fs@2.1.2
   no known CVEs
   surface: fs-write
A  @npmcli/move-file@1.1.2
   no known CVEs
   surface: fs-write
A  @npmcli/move-file@2.0.1
   no known CVEs
   surface: fs-write
A  @playwright/test@1.57.0
   no known CVEs
   surface: bin
A  @smithy/config-resolver@4.1.5
   1 CVEs: 1 LOW
   surface: none
A  @swc/helpers@0.5.15
   no known CVEs
   surface: fs-write
A  @swc/helpers@0.5.21
   no known CVEs
   surface: fs-write
A  @tailwindcss/node@4.1.15
   no known CVEs
   surface: dynamic-import
A  @tailwindcss/node@4.1.16
   no known CVEs
   surface: dynamic-import
A  @tootallnate/once@1.1.2
   1 CVEs: 1 LOW
   surface: none
A  @tootallnate/once@2.0.0
   1 CVEs: 1 LOW
   surface: none
A  @typescript-eslint/typescript-estree@6.7.2
   no known CVEs
   surface: fs-write
A  @vitejs/plugin-basic-ssl@2.1.0
   no known CVEs
   surface: fs-write
A  @vitejs/plugin-react@5.1.2
   no known CVEs
   surface: dynamic-import
A  @vitejs/plugin-react-swc@4.2.2
   no known CVEs
   surface: dynamic-import
A  @vitest/coverage-v8@4.0.16
   no known CVEs
   surface: dynamic-import
A  @vitest/mocker@4.0.16
   no known CVEs
   surface: dynamic-import
A  acorn@8.15.0
   no known CVEs
   surface: bin
A  acorn@8.8.1
   no known CVEs
   surface: bin
A  acorn@8.16.0
   no known CVEs
   surface: bin
A  argparse@2.0.1
   no known CVEs
   surface: fs-write
A  astring@1.9.0
   no known CVEs
   surface: bin
A  async@3.2.4
   no known CVEs
   surface: fs-write
A  atomically@1.7.0
   no known CVEs
   surface: fs-write
A  autoprefixer@10.4.19
   no known CVEs
   surface: bin
A  baseline-browser-mapping@2.10.19
   no known CVEs
   surface: bin
A  baseline-browser-mapping@2.9.7
   no known CVEs
   surface: bin
A  bl@4.1.0
   no known CVEs
   surface: fs-write
A  bl@6.1.0
   no known CVEs
   surface: fs-write
A  bmp-js@0.1.0
   no known CVEs
   surface: fs-write
A  body-parser@1.20.3
   1 CVEs: 1 LOW
   surface: none
A  body-parser@2.2.2
   1 CVEs: 1 LOW
   surface: none
A  bs-logger@0.2.6
   no known CVEs
   surface: fs-write
A  btoa@1.2.1
   no known CVEs
   surface: bin
A  c12@1.11.2
   no known CVEs
   surface: fs-write
A  c8@7.13.0
   no known CVEs
   surface: bin
A  cacache@16.1.3
   no known CVEs
   surface: fs-write
A  cacache@15.3.0
   no known CVEs
   surface: fs-write
A  cacache@18.0.4
   no known CVEs
   surface: fs-write
A  chevrotain@12.0.0
   no known CVEs
   surface: fs-write
A  color-support@1.1.3
   no known CVEs
   surface: bin
A  conf@10.2.0
   no known CVEs
   surface: fs-write
A  cookie@0.4.2
   1 CVEs: 1 LOW
   surface: none
A  cookie@0.4.1
   1 CVEs: 1 LOW
   surface: none
A  cosmiconfig@8.3.6
   no known CVEs
   surface: dynamic-import
A  cronstrue@2.59.0
   no known CVEs
   surface: bin
A  css-declaration-sorter@7.3.0
   no known CVEs
   surface: dynamic-import
A  cssesc@3.0.0
   no known CVEs
   surface: bin
A  cytoscape@3.33.2
   no known CVEs
   surface: fs-write
A  diff@4.0.2
   1 CVEs: 1 LOW
   surface: none
A  diff@7.0.0
   1 CVEs: 1 LOW
   surface: none
A  diff@8.0.2
   1 CVEs: 1 LOW
   surface: none
A  dotenv-cli@6.0.0
   no known CVEs
   surface: bin
A  esprima@4.0.1
   no known CVEs
   surface: bin
A  exif-parser@0.1.12
   no known CVEs
   surface: fs-write
A  fastest-levenshtein@1.0.16
   no known CVEs
   surface: fs-write
A  fictional@1.0.0
   no known CVEs
   surface: fs-write
A  flat@6.0.1
   no known CVEs
   surface: bin
A  fs-extra@11.3.2
   no known CVEs
   surface: fs-write
A  fs-extra@11.1.1
   no known CVEs
   surface: fs-write
A  fs-extra@11.3.0
   no known CVEs
   surface: fs-write
A  fs-extra@9.1.0
   no known CVEs
   surface: fs-write
A  fs-extra@11.3.3
   no known CVEs
   surface: fs-write
A  fs-extra@10.1.0
   no known CVEs
   surface: fs-write
A  fs-extra@8.1.0
   no known CVEs
   surface: fs-write
A  fs-extra@7.0.1
   no known CVEs
   surface: fs-write
A  gifwrap@0.9.4
   no known CVEs
   surface: fs-write
A  glob@11.1.0
   no known CVEs
   surface: bin
A  glob@10.5.0
   no known CVEs
   surface: bin
A  google-p12-pem@3.1.4
   no known CVEs
   surface: bin
A  graceful-fs@4.2.11
   no known CVEs
   surface: fs-write
A  graphql-introspection-json-to-sdl@1.0.3
   no known CVEs
   surface: bin
A  he@1.2.0
   no known CVEs
   surface: bin
A  human-id@4.1.1
   no known CVEs
   surface: bin
A  input-format@0.3.14
   no known CVEs
   surface: fs-write
A  interactive-commander@0.5.194
   no known CVEs
   surface: dynamic-import
A  is-ci@3.0.1
   no known CVEs
   surface: bin
A  is-ci@2.0.0
   no known CVEs
   surface: bin
A  is-docker@2.2.1
   no known CVEs
   surface: bin
A  is-docker@3.0.0
   no known CVEs
   surface: bin
A  is-inside-container@1.0.0
   no known CVEs
   surface: bin
A  isexe@2.0.0
   no known CVEs
   surface: fs-write
A  istanbul-lib-report@3.0.0
   no known CVEs
   surface: fs-write
A  istanbul-lib-report@3.0.1
   no known CVEs
   surface: fs-write
A  jest@29.7.0
   no known CVEs
   surface: bin
A  jsesc@3.1.0
   no known CVEs
   surface: bin
A  jsonfile@6.1.0
   no known CVEs
   surface: fs-write
A  jsonfile@4.0.0
   no known CVEs
   surface: fs-write
A  lilconfig@3.1.3
   no known CVEs
   surface: dynamic-import
A  local-pkg@1.1.2
   no known CVEs
   surface: dynamic-import
A  loose-envify@1.4.0
   no known CVEs
   surface: bin
A  magicast@0.3.5
   no known CVEs
   surface: fs-write
A  memfs@3.5.3
   no known CVEs
   surface: fs-write
A  mime@2.6.0
   no known CVEs
   surface: bin
A  mkdirp@1.0.4
   no known CVEs
   surface: bin
A  mkdirp@0.5.6
   no known CVEs
   surface: bin
A  mssql@11.0.1
   no known CVEs
   surface: bin
A  nanoid@3.3.11
   no known CVEs
   surface: bin
A  nanoid@3.3.8
   no known CVEs
   surface: bin
A  node-emoji@1.11.0
   no known CVEs
   surface: fs-write
A  nopt@6.0.0
   no known CVEs
   surface: bin
A  nopt@5.0.0
   no known CVEs
   surface: bin
A  nopt@7.2.1
   no known CVEs
   surface: bin
A  omggif@1.0.10
   no known CVEs
   surface: fs-write
A  pixelmatch@4.0.2
   no known CVEs
   surface: bin
A  pkg-types@1.3.1
   no known CVEs
   surface: fs-write
A  pkg-types@2.3.0
   no known CVEs
   surface: fs-write
A  promise@7.3.1
   no known CVEs
   surface: fs-write
A  pump@3.0.0
   no known CVEs
   surface: fs-write
A  rc9@2.1.2
   no known CVEs
   surface: fs-write
A  react-phone-number-input@3.4.12
   no known CVEs
   surface: fs-write
A  rw@1.3.3
   no known CVEs
   surface: fs-write
A  sdp-transform@2.15.0
   no known CVEs
   surface: bin
A  semver@7.7.3
   no known CVEs
   surface: bin
A  semver@5.7.2
   no known CVEs
   surface: bin
A  semver@6.3.1
   no known CVEs
   surface: bin
A  semver@7.5.4
   no known CVEs
   surface: bin
A  sha.js@2.4.12
   no known CVEs
   surface: bin
A  spacetime@7.1.4
   no known CVEs
   surface: fs-write
A  tar-fs@2.1.4
   no known CVEs
   surface: fs-write
A  tar-stream@2.2.0
   no known CVEs
   surface: fs-write
A  title@4.0.1
   no known CVEs
   surface: bin
A  ts-api-utils@1.0.3
   no known CVEs
   surface: dynamic-import
A  ts-morph@27.0.2
   no known CVEs
   surface: fs-write
A  tsc-absolute@1.0.0
   no known CVEs
   surface: bin
A  tsconfck@3.1.3
   no known CVEs
   surface: bin
A  ua-parser-js@1.0.40
   no known CVEs
   surface: bin
A  ulid@2.4.0
   no known CVEs
   surface: bin
A  unplugin@1.0.1
   no known CVEs
   surface: fs-write
A  unplugin@2.3.11
   no known CVEs
   surface: fs-write
A  vite-plugin-dts@4.5.4
   no known CVEs
   surface: fs-write
A  which@2.0.2
   no known CVEs
   surface: bin
A  which@1.3.1
   no known CVEs
   surface: bin
A  which@4.0.0
   no known CVEs
   surface: bin
A  write-file-atomic@4.0.2
   no known CVEs
   surface: fs-write
A  y18n@5.0.8
   no known CVEs
   surface: fs-write
A  y18n@4.0.3
   no known CVEs
   surface: fs-write
A  zod-to-json-schema@3.25.0
   no known CVEs
   surface: fs-write
A  zod-to-json-schema@3.25.1
   no known CVEs
   surface: fs-write
A  @0no-co/graphql.web@1.2.0
   no known CVEs
   surface: none
A  @ai-sdk/anthropic@1.2.11
   no known CVEs
   surface: none
A  @ai-sdk/google@1.2.19
   no known CVEs
   surface: none
A  @ai-sdk/groq@1.2.3
   no known CVEs
   surface: none
A  @ai-sdk/mistral@1.2.8
   no known CVEs
   surface: none
A  @ai-sdk/openai@1.3.22
   no known CVEs
   surface: none
A  @ai-sdk/provider@1.1.0
   no known CVEs
   surface: none
A  @ai-sdk/provider@1.1.3
   no known CVEs
   surface: none
A  @ai-sdk/react@1.2.12
   no known CVEs
   surface: none
A  @ai-sdk/react@1.2.5
   no known CVEs
   surface: none
A  @ai-sdk/ui-utils@1.2.11
   no known CVEs
   surface: none
A  @ai-sdk/ui-utils@1.2.4
   no known CVEs
   surface: none
A  @alloc/quick-lru@5.2.0
   no known CVEs
   surface: none
A  @ampproject/remapping@2.2.1
   no known CVEs
   surface: none
A  @antfu/install-pkg@1.1.0
   no known CVEs
   surface: none
A  @antfu/utils@0.7.8
   no known CVEs
   surface: none
A  @arr/every@1.0.1
   no known CVEs
   surface: none
A  @aws-crypto/sha256-browser@5.2.0
   no known CVEs
   surface: none
A  @aws-crypto/sha256-js@5.2.0
   no known CVEs
   surface: none
A  @aws-crypto/supports-web-crypto@5.2.0
   no known CVEs
   surface: none
A  @aws-crypto/util@5.2.0
   no known CVEs
   surface: none
A  @aws-sdk/client-sso@3.817.0
   no known CVEs
   surface: none
A  @aws-sdk/core@3.816.0
   no known CVEs
   surface: none
A  @aws-sdk/credential-provider-cognito-identity@3.817.0
   no known CVEs
   surface: none
A  @aws-sdk/credential-provider-env@3.816.0
   no known CVEs
   surface: none
A  @aws-sdk/credential-provider-http@3.816.0
   no known CVEs
   surface: none
A  @aws-sdk/credential-provider-ini@3.817.0
   no known CVEs
   surface: none
A  @aws-sdk/credential-provider-node@3.817.0
   no known CVEs
   surface: none
A  @aws-sdk/credential-provider-sso@3.817.0
   no known CVEs
   surface: none
A  @aws-sdk/credential-provider-web-identity@3.817.0
   no known CVEs
   surface: none
A  @aws-sdk/credential-providers@3.817.0
   no known CVEs
   surface: none
A  @aws-sdk/endpoint-cache@3.804.0
   no known CVEs
   surface: none
A  @aws-sdk/middleware-endpoint-discovery@3.808.0
   no known CVEs
   surface: none
A  @aws-sdk/middleware-host-header@3.804.0
   no known CVEs
   surface: none
A  @aws-sdk/middleware-logger@3.804.0
   no known CVEs
   surface: none
A  @aws-sdk/middleware-recursion-detection@3.804.0
   no known CVEs
   surface: none
A  @aws-sdk/middleware-user-agent@3.816.0
   no known CVEs
   surface: none
A  @aws-sdk/region-config-resolver@3.808.0
   no known CVEs
   surface: none
A  @aws-sdk/types@3.804.0
   no known CVEs
   surface: none
A  @aws-sdk/util-dynamodb@3.817.0
   no known CVEs
   surface: none
A  @aws-sdk/util-endpoints@3.808.0
   no known CVEs
   surface: none
A  @aws-sdk/util-locate-window@3.208.0
   no known CVEs
   surface: none
A  @aws-sdk/util-user-agent-browser@3.804.0
   no known CVEs
   surface: none
A  @aws-sdk/util-user-agent-node@3.816.0
   no known CVEs
   surface: none
A  @axiomhq/js@1.2.0
   no known CVEs
   surface: none
A  @axiomhq/winston@1.2.0
   no known CVEs
   surface: none
A  @azure/abort-controller@2.1.2
   no known CVEs
   surface: none
A  @azure/abort-controller@1.1.0
   no known CVEs
   surface: none
A  @azure/core-auth@1.9.0
   no known CVEs
   surface: none
A  @azure/core-client@1.9.3
   no known CVEs
   surface: none
A  @azure/core-http-compat@1.3.0
   no known CVEs
   surface: none
A  @azure/core-lro@2.4.0
   no known CVEs
   surface: none
A  @azure/core-paging@1.4.0
   no known CVEs
   surface: none
A  @azure/core-tracing@1.0.1
   no known CVEs
   surface: none
A  @azure/core-util@1.11.0
   no known CVEs
   surface: none
A  @azure/keyvault-keys@4.6.0
   no known CVEs
   surface: none
A  @azure/logger@1.0.3
   no known CVEs
   surface: none
A  @azure/msal-common@15.2.1
   no known CVEs
   surface: none
A  @babel/code-frame@7.27.1
   no known CVEs
   surface: none
A  @babel/compat-data@7.28.5
   no known CVEs
   surface: none
A  @babel/compat-data@7.26.8
   no known CVEs
   surface: none
A  @babel/generator@7.28.5
   no known CVEs
   surface: none
A  @babel/helper-compilation-targets@7.27.2
   no known CVEs
   surface: none
A  @babel/helper-compilation-targets@7.27.0
   no known CVEs
   surface: none
A  @babel/helper-globals@7.28.0
   no known CVEs
   surface: none
A  @babel/helper-module-imports@7.27.1
   no known CVEs
   surface: none
A  @babel/helper-module-imports@7.25.9
   no known CVEs
   surface: none
A  @babel/helper-module-transforms@7.28.3
   no known CVEs
   surface: none
A  @babel/helper-module-transforms@7.26.0
   no known CVEs
   surface: none
A  @babel/helper-plugin-utils@7.27.1
   no known CVEs
   surface: none
A  @babel/helper-plugin-utils@7.26.5
   no known CVEs
   surface: none
A  @babel/helper-string-parser@7.27.1
   no known CVEs
   surface: none
A  @babel/helper-validator-identifier@7.28.5
   no known CVEs
   surface: none
A  @babel/helper-validator-option@7.27.1
   no known CVEs
   surface: none
A  @babel/helper-validator-option@7.25.9
   no known CVEs
   surface: none
A  @babel/helpers@7.28.4
   no known CVEs
   surface: none
A  @babel/helpers@7.27.0
   no known CVEs
   surface: none
A  @babel/plugin-syntax-async-generators@7.8.4
   no known CVEs
   surface: none
A  @babel/plugin-syntax-bigint@7.8.3
   no known CVEs
   surface: none
A  @babel/plugin-syntax-class-properties@7.12.13
   no known CVEs
   surface: none
A  @babel/plugin-syntax-import-assertions@7.26.0
   no known CVEs
   surface: none
A  @babel/plugin-syntax-import-meta@7.10.4
   no known CVEs
   surface: none
A  @babel/plugin-syntax-json-strings@7.8.3
   no known CVEs
   surface: none
A  @babel/plugin-syntax-jsx@7.23.3
   no known CVEs
   surface: none
A  @babel/plugin-syntax-logical-assignment-operators@7.10.4
   no known CVEs
   surface: none
A  @babel/plugin-syntax-nullish-coalescing-operator@7.8.3
   no known CVEs
   surface: none
A  @babel/plugin-syntax-numeric-separator@7.10.4
   no known CVEs
   surface: none
A  @babel/plugin-syntax-object-rest-spread@7.8.3
   no known CVEs
   surface: none
A  @babel/plugin-syntax-optional-catch-binding@7.8.3
   no known CVEs
   surface: none
A  @babel/plugin-syntax-optional-chaining@7.8.3
   no known CVEs
   surface: none
A  @babel/plugin-syntax-top-level-await@7.14.5
   no known CVEs
   surface: none
A  @babel/plugin-syntax-typescript@7.23.3
   no known CVEs
   surface: none
A  @babel/plugin-transform-react-jsx-self@7.27.1
   no known CVEs
   surface: none
A  @babel/plugin-transform-react-jsx-source@7.27.1
   no known CVEs
   surface: none
A  @babel/runtime@7.28.4
   no known CVEs
   surface: none
A  @babel/template@7.27.2
   no known CVEs
   surface: none
A  @babel/traverse@7.28.5
   no known CVEs
   surface: none
A  @babel/types@7.29.0
   no known CVEs
   surface: none
A  @babel/types@7.28.5
   no known CVEs
   surface: none
A  @base-ui/react@1.0.0
   no known CVEs
   surface: none
A  @base-ui/utils@0.2.3
   no known CVEs
   surface: none
A  @bcoe/v8-coverage@1.0.2
   no known CVEs
   surface: none
A  @bcoe/v8-coverage@0.2.3
   no known CVEs
   surface: none
A  @biomejs/cli-darwin-arm64@2.3.10
   no known CVEs
   surface: none
A  @biomejs/js-api@3.0.0
   no known CVEs
   surface: none
A  @borewit/text-codec@0.1.1
   no known CVEs
   surface: none
A  @boxyhq/metrics@0.2.10
   no known CVEs
   surface: none
A  @boxyhq/saml20@1.12.1
   no known CVEs
   surface: none
A  @braintree/sanitize-url@7.1.2
   no known CVEs
   surface: none
A  @bufbuild/protobuf@1.10.1
   no known CVEs
   surface: none
A  @bugsnag/cuid@3.2.1
   no known CVEs
   surface: none
A  @bundled-es-modules/cookie@2.0.1
   no known CVEs
   surface: none
A  @bundled-es-modules/statuses@1.0.1
   no known CVEs
   surface: none
A  @changesets/assemble-release-plan@6.0.8
   no known CVEs
   surface: none
A  @changesets/changelog-git@0.2.1
   no known CVEs
   surface: none
A  @changesets/changelog-github@0.5.1
   no known CVEs
   surface: none
A  @changesets/config@3.1.1
   no known CVEs
   surface: none
A  @changesets/errors@0.2.0
   no known CVEs
   surface: none
A  @changesets/get-dependents-graph@2.1.3
   no known CVEs
   surface: none
A  @changesets/get-release-plan@4.0.12
   no known CVEs
   surface: none
A  @changesets/get-version-range-type@0.4.0
   no known CVEs
   surface: none
A  @changesets/git@3.0.4
   no known CVEs
   surface: none
A  @changesets/logger@0.1.1
   no known CVEs
   surface: none
A  @changesets/parse@0.4.1
   no known CVEs
   surface: none
A  @changesets/pre@2.0.2
   no known CVEs
   surface: none
A  @changesets/read@0.6.5
   no known CVEs
   surface: none
A  @changesets/should-skip-package@0.1.2
   no known CVEs
   surface: none
A  @changesets/types@4.1.0
   no known CVEs
   surface: none
A  @changesets/types@6.1.0
   no known CVEs
   surface: none
A  @chevrotain/cst-dts-gen@12.0.0
   no known CVEs
   surface: none
A  @chevrotain/cst-dts-gen@10.5.0
   no known CVEs
   surface: none
A  @chevrotain/gast@12.0.0
   no known CVEs
   surface: none
A  @chevrotain/gast@10.5.0
   no known CVEs
   surface: none
A  @chevrotain/regexp-to-ast@12.0.0
   no known CVEs
   surface: none
A  @chevrotain/types@12.0.0
   no known CVEs
   surface: none
A  @chevrotain/types@10.5.0
   no known CVEs
   surface: none
A  @chevrotain/utils@12.0.0
   no known CVEs
   surface: none
A  @clack/core@0.5.0
   no known CVEs
   surface: none
A  @clack/prompts@0.11.0
   no known CVEs
   surface: none
A  @csstools/color-helpers@5.1.0
   no known CVEs
   surface: none
A  @csstools/css-calc@2.1.4
   no known CVEs
   surface: none
A  @csstools/css-color-parser@3.1.0
   no known CVEs
   surface: none
A  @csstools/css-parser-algorithms@3.0.5
   no known CVEs
   surface: none
A  @csstools/css-tokenizer@3.0.4
   no known CVEs
   surface: none
A  @dabh/diagnostics@2.0.3
   no known CVEs
   surface: none
A  @daily-co/daily-react@0.23.2
   no known CVEs
   surface: none
A  @depot/cli-darwin-arm64@0.0.1-cli.2.80.0
   no known CVEs
   surface: none
A  @discoveryjs/json-ext@0.5.7
   no known CVEs
   surface: none
A  @dmsnell/diff-match-patch@1.1.0
   no known CVEs
   surface: none
A  @dub/analytics@0.0.27
   no known CVEs
   surface: none
A  @dub/embed-core@0.0.18
   no known CVEs
   surface: none
A  @dub/embed-react@0.0.18
   no known CVEs
   surface: none
A  @emotion/babel-plugin@11.7.2
   no known CVEs
   surface: none
A  @emotion/cache@11.7.1
   no known CVEs
   surface: none
A  @emotion/hash@0.8.0
   no known CVEs
   surface: none
A  @emotion/is-prop-valid@0.8.8
   no known CVEs
   surface: none
A  @emotion/memoize@0.7.5
   no known CVEs
   surface: none
A  @emotion/memoize@0.7.4
   no known CVEs
   surface: none
A  @emotion/react@11.9.0
   no known CVEs
   surface: none
A  @emotion/serialize@1.0.3
   no known CVEs
   surface: none
A  @emotion/sheet@1.1.0
   no known CVEs
   surface: none
A  @emotion/unitless@0.7.5
   no known CVEs
   surface: none
A  @emotion/utils@1.1.0
   no known CVEs
   surface: none
A  @emotion/weak-memoize@0.2.5
   no known CVEs
   surface: none
A  @envelop/core@5.2.3
   no known CVEs
   surface: none
A  @envelop/instrumentation@1.0.0
   no known CVEs
   surface: none
A  @envelop/types@5.2.1
   no known CVEs
   surface: none
A  @esbuild/darwin-arm64@0.23.1
   no known CVEs
   surface: none
A  @esbuild/darwin-arm64@0.25.12
   no known CVEs
   surface: none
A  @evyweb/ioctopus@1.2.0
   no known CVEs
   surface: none
A  @ewsjs/ntlm-client@3.0.1
   no known CVEs
   surface: none
A  @floating-ui/core@1.7.5
   no known CVEs
   surface: none
A  @floating-ui/core@1.7.3
   no known CVEs
   surface: none
A  @floating-ui/dom@1.7.4
   no known CVEs
   surface: none
A  @floating-ui/react-dom@2.1.6
   no known CVEs
   surface: none
A  @floating-ui/utils@0.2.10
   no known CVEs
   surface: none
A  @floating-ui/utils@0.2.11
   no known CVEs
   surface: none
A  @formatjs/intl-localematcher@0.6.2
   no known CVEs
   surface: none
A  @formbricks/js@4.3.0
   no known CVEs
   surface: none
A  @formkit/auto-animate@1.0.0-beta.5
   no known CVEs
   surface: none
A  @gar/promisify@1.1.3
   no known CVEs
   surface: none
A  @gitbeaker/requester-utils@39.34.3
   no known CVEs
   surface: none
A  @glidejs/glide@3.5.2
   no known CVEs
   surface: none
A  @golevelup/ts-jest@0.4.0
   no known CVEs
   surface: none
A  @google-cloud/precise-date@4.0.0
   no known CVEs
   surface: none
A  @googleapis/admin@23.5.0
   no known CVEs
   surface: none
A  @googleapis/oauth2@1.0.7
   no known CVEs
   surface: none
A  @graphql-codegen/add@5.0.3
   no known CVEs
   surface: none
A  @graphql-codegen/client-preset@4.8.0
   no known CVEs
   surface: none
A  @graphql-codegen/core@4.0.2
   no known CVEs
   surface: none
A  @graphql-codegen/gql-tag-operations@4.0.17
   no known CVEs
   surface: none
A  @graphql-codegen/plugin-helpers@5.1.0
   no known CVEs
   surface: none
A  @graphql-codegen/schema-ast@4.1.0
   no known CVEs
   surface: none
A  @graphql-codegen/typed-document-node@5.1.1
   no known CVEs
   surface: none
A  @graphql-codegen/typescript@4.1.6
   no known CVEs
   surface: none
A  @graphql-codegen/typescript-operations@4.6.0
   no known CVEs
   surface: none
A  @graphql-codegen/visitor-plugin-common@5.8.0
   no known CVEs
   surface: none
A  @graphql-hive/signal@1.0.0
   no known CVEs
   surface: none
A  @graphql-tools/batch-execute@9.0.15
   no known CVEs
   surface: none
A  @graphql-tools/delegate@10.2.17
   no known CVEs
   surface: none
A  @graphql-tools/documents@1.0.1
   no known CVEs
   surface: none
A  @graphql-tools/executor-common@0.0.4
   no known CVEs
   surface: none
A  @graphql-tools/github-loader@8.0.20
   no known CVEs
   surface: none
A  @graphql-tools/graphql-file-loader@8.0.19
   no known CVEs
   surface: none
A  @graphql-tools/graphql-tag-pluck@8.3.19
   no known CVEs
   surface: none
A  @graphql-tools/import@7.0.18
   no known CVEs
   surface: none
A  @graphql-tools/json-file-loader@8.0.18
   no known CVEs
   surface: none
A  @graphql-tools/merge@9.0.24
   no known CVEs
   surface: none
A  @graphql-tools/optimize@2.0.0
   no known CVEs
   surface: none
A  @graphql-tools/relay-operation-optimizer@7.0.19
   no known CVEs
   surface: none
A  @graphql-tools/schema@10.0.23
   no known CVEs
   surface: none
A  @graphql-tools/utils@10.8.6
   no known CVEs
   surface: none
A  @graphql-tools/wrap@10.0.35
   no known CVEs
   surface: none
A  @graphql-typed-document-node/core@3.2.0
   no known CVEs
   surface: none
A  @hookform/error-message@2.0.0
   no known CVEs
   surface: none
A  @hubspot/api-client@6.0.1
   no known CVEs
   surface: none
A  @iconify/types@2.0.0
   no known CVEs
   surface: none
A  @img/colour@1.0.0
   no known CVEs
   surface: none
A  @img/sharp-libvips-darwin-arm64@1.0.4
   no known CVEs
   surface: none
A  @img/sharp-libvips-darwin-arm64@1.2.4
   no known CVEs
   surface: none
A  @inkjs/ui@2.0.0
   no known CVEs
   surface: none
A  @inquirer/ansi@1.0.2
   no known CVEs
   surface: none
A  @inquirer/checkbox@4.3.2
   no known CVEs
   surface: none
A  @inquirer/confirm@5.1.21
   no known CVEs
   surface: none
A  @inquirer/core@10.3.2
   no known CVEs
   surface: none
A  @inquirer/editor@4.2.23
   no known CVEs
   surface: none
A  @inquirer/expand@4.0.23
   no known CVEs
   surface: none
A  @inquirer/figures@1.0.15
   no known CVEs
   surface: none
A  @inquirer/input@4.3.1
   no known CVEs
   surface: none
A  @inquirer/number@3.0.23
   no known CVEs
   surface: none
A  @inquirer/password@4.0.23
   no known CVEs
   surface: none
A  @inquirer/prompts@7.10.1
   no known CVEs
   surface: none
A  @inquirer/prompts@7.8.0
   no known CVEs
   surface: none
A  @inquirer/rawlist@4.1.11
   no known CVEs
   surface: none
A  @inquirer/search@3.2.2
   no known CVEs
   surface: none
A  @inquirer/select@4.4.2
   no known CVEs
   surface: none
A  @inquirer/type@3.0.10
   no known CVEs
   surface: none
A  @ioredis/commands@1.2.0
   no known CVEs
   surface: none
A  @isaacs/cliui@8.0.2
   no known CVEs
   surface: none
A  @isaacs/fs-minipass@4.0.1
   no known CVEs
   surface: none
A  @istanbuljs/schema@0.1.3
   no known CVEs
   surface: none
A  @jest/console@29.7.0
   no known CVEs
   surface: none
A  @jest/environment@29.7.0
   no known CVEs
   surface: none
A  @jest/expect@29.7.0
   no known CVEs
   surface: none
A  @jest/expect-utils@29.7.0
   no known CVEs
   surface: none
A  @jest/fake-timers@29.7.0
   no known CVEs
   surface: none
A  @jest/globals@29.7.0
   no known CVEs
   surface: none
A  @jest/reporters@29.7.0
   no known CVEs
   surface: none
A  @jest/schemas@29.6.3
   no known CVEs
   surface: none
A  @jest/source-map@29.6.3
   no known CVEs
   surface: none
A  @jest/test-result@29.7.0
   no known CVEs
   surface: none
A  @jest/types@29.6.3
   no known CVEs
   surface: none
A  @jimp/bmp@0.16.1
   no known CVEs
   surface: none
A  @jimp/custom@0.16.1
   no known CVEs
   surface: none
A  @jimp/gif@0.16.1
   no known CVEs
   surface: none
A  @jimp/jpeg@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-blit@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-blur@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-circle@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-color@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-contain@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-cover@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-crop@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-displace@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-dither@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-fisheye@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-flip@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-gaussian@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-invert@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-mask@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-normalize@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-print@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-resize@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-rotate@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-scale@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-shadow@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugin-threshold@0.16.1
   no known CVEs
   surface: none
A  @jimp/plugins@0.16.1
   no known CVEs
   surface: none
A  @jimp/png@0.16.1
   no known CVEs
   surface: none
A  @jimp/tiff@0.16.1
   no known CVEs
   surface: none
A  @jimp/types@0.16.1
   no known CVEs
   surface: none
A  @jimp/utils@0.16.1
   no known CVEs
   surface: none
A  @jridgewell/gen-mapping@0.3.13
   no known CVEs
   surface: none
A  @jridgewell/remapping@2.3.5
   no known CVEs
   surface: none
A  @jridgewell/resolve-uri@3.1.1
   no known CVEs
   surface: none
A  @jridgewell/source-map@0.3.5
   no known CVEs
   surface: none
A  @jridgewell/sourcemap-codec@1.5.5
   no known CVEs
   surface: none
A  @jridgewell/trace-mapping@0.3.31
   no known CVEs
   surface: none
A  @jridgewell/trace-mapping@0.3.30
   no known CVEs
   surface: none
A  @jridgewell/trace-mapping@0.3.9
   no known CVEs
   surface: none
A  @js-joda/core@5.6.4
   no known CVEs
   surface: none
A  @js-sdsl/ordered-map@4.4.2
   no known CVEs
   surface: none
A  @jsonhero/path@1.0.21
   no known CVEs
   surface: none
A  @lexical/clipboard@0.9.0
   no known CVEs
   surface: none
A  @lexical/code@0.9.0
   no known CVEs
   surface: none
A  @lexical/dragon@0.9.0
   no known CVEs
   surface: none
A  @lexical/hashtag@0.9.0
   no known CVEs
   surface: none
A  @lexical/history@0.9.0
   no known CVEs
   surface: none
A  @lexical/html@0.9.0
   no known CVEs
   surface: none
A  @lexical/link@0.9.0
   no known CVEs
   surface: none
A  @lexical/list@0.9.0
   no known CVEs
   surface: none
A  @lexical/mark@0.9.0
   no known CVEs
   surface: none
A  @lexical/markdown@0.9.0
   no known CVEs
   surface: none
A  @lexical/offset@0.9.0
   no known CVEs
   surface: none
A  @lexical/overflow@0.9.0
   no known CVEs
   surface: none
A  @lexical/plain-text@0.9.0
   no known CVEs
   surface: none
A  @lexical/react@0.9.0
   no known CVEs
   surface: none
A  @lexical/rich-text@0.9.0
   no known CVEs
   surface: none
A  @lexical/selection@0.9.0
   no known CVEs
   surface: none
A  @lexical/table@0.9.0
   no known CVEs
   surface: none
A  @lexical/text@0.9.0
   no known CVEs
   surface: none
A  @lexical/utils@0.9.0
   no known CVEs
   surface: none
A  @lexical/yjs@0.9.0
   no known CVEs
   surface: none
A  @libsql/sqlite3@0.3.1
   no known CVEs
   surface: none
A  @lingo.dev/_react@0.7.3
   no known CVEs
   surface: none
A  @lingo.dev/_spec@0.44.4
   no known CVEs
   surface: none
A  @livekit/mutex@1.1.1
   no known CVEs
   surface: none
A  @livekit/protocol@1.39.3
   no known CVEs
   surface: none
A  @ljharb/through@2.3.13
   no known CVEs
   surface: none
A  @lukeed/csprng@1.1.0
   no known CVEs
   surface: none
A  @manypkg/find-root@1.1.0
   no known CVEs
   surface: none
A  @manypkg/get-packages@1.1.3
   no known CVEs
   surface: none
A  @microsoft/api-extractor-model@7.32.2
   no known CVEs
   surface: none
A  @microsoft/microsoft-graph-types-beta@0.42.0-preview
   no known CVEs
   surface: none
A  @microsoft/tsdoc@0.15.1
   no known CVEs
   surface: none
A  @microsoft/tsdoc@0.16.0
   no known CVEs
   surface: none
A  @mrleebo/prisma-ast@0.13.0
   no known CVEs
   surface: none
A  @nest-lab/throttler-storage-redis@1.0.0
   no known CVEs
   surface: none
A  @nestjs/axios@4.0.0
   no known CVEs
   surface: none
A  @nestjs/bull@11.0.4
   no known CVEs
   surface: none
A  @nestjs/bull-shared@11.0.4
   no known CVEs
   surface: none
A  @nestjs/config@3.2.0
   no known CVEs
   surface: none
A  @nestjs/jwt@10.2.0
   no known CVEs
   surface: none
A  @nestjs/mapped-types@2.0.5
   no known CVEs
   surface: none
A  @nestjs/passport@10.0.3
   no known CVEs
   surface: none
A  @nestjs/testing@10.4.20
   no known CVEs
   surface: none
A  @nestjs/throttler@6.2.1
   no known CVEs
   surface: none
A  @next-auth/prisma-adapter@1.0.4
   no known CVEs
   surface: none
A  @next/bundle-analyzer@16.1.5
   no known CVEs
   surface: none
A  @next/env@16.2.3
   no known CVEs
   surface: none
A  @next/env@15.5.15
   no known CVEs
   surface: none
A  @next/third-parties@14.2.5
   no known CVEs
   surface: none
A  @noble/ciphers@0.5.3
   no known CVEs
   surface: none
A  @noble/curves@1.1.0
   no known CVEs
   surface: none
A  @noble/curves@1.2.0
   no known CVEs
   surface: none
A  @nodelib/fs.scandir@2.1.5
   no known CVEs
   surface: none
A  @nodelib/fs.stat@2.0.5
   no known CVEs
   surface: none
A  @nodelib/fs.walk@1.2.8
   no known CVEs
   surface: none
A  @npmcli/fs@3.1.1
   no known CVEs
   surface: none
A  @oclif/color@1.0.13
   no known CVEs
   surface: none
A  @oclif/linewrap@1.0.0
   no known CVEs
   surface: none
A  @oclif/plugin-help@5.1.20
   no known CVEs
   surface: none
A  @oclif/plugin-not-found@2.3.23
   no known CVEs
   surface: none
A  @oclif/screen@3.0.8
   no known CVEs
   surface: none
A  @octokit/app@15.1.6
   no known CVEs
   surface: none
A  @octokit/auth-app@7.2.2
   no known CVEs
   surface: none
A  @octokit/auth-oauth-app@8.1.4
   no known CVEs
   surface: none
A  @octokit/auth-oauth-device@7.1.5
   no known CVEs
   surface: none
A  @octokit/auth-oauth-user@5.1.6
   no known CVEs
   surface: none
A  @octokit/auth-token@5.1.2
   no known CVEs
   surface: none
A  @octokit/auth-unauthenticated@6.1.3
   no known CVEs
   surface: none
A  @octokit/core@6.1.6
   no known CVEs
   surface: none
A  @octokit/endpoint@10.1.4
   no known CVEs
   surface: none
A  @octokit/graphql@8.2.2
   no known CVEs
   surface: none
A  @octokit/oauth-app@7.1.6
   no known CVEs
   surface: none
A  @octokit/oauth-authorization-url@7.1.1
   no known CVEs
   surface: none
A  @octokit/oauth-methods@5.1.5
   no known CVEs
   surface: none
A  @octokit/openapi-types@24.2.0
   no known CVEs
   surface: none
A  @octokit/openapi-types@25.1.0
   no known CVEs
   surface: none
A  @octokit/openapi-webhooks-types@11.0.0
   no known CVEs
   surface: none
A  @octokit/plugin-paginate-graphql@5.2.4
   no known CVEs
   surface: none
A  @octokit/plugin-paginate-rest@11.6.0
   no known CVEs
   surface: none
A  @octokit/plugin-paginate-rest@12.0.0
   no known CVEs
   surface: none
A  @octokit/plugin-rest-endpoint-methods@13.5.0
   no known CVEs
   surface: none
A  @octokit/plugin-retry@7.2.1
   no known CVEs
   surface: none
A  @octokit/plugin-throttling@9.6.1
   no known CVEs
   surface: none
A  @octokit/request-error@6.1.8
   no known CVEs
   surface: none
A  @octokit/types@13.10.0
   no known CVEs
   surface: none
A  @octokit/types@14.1.0
   no known CVEs
   surface: none
A  @octokit/webhooks@13.9.1
   no known CVEs
   surface: none
A  @octokit/webhooks-methods@5.1.1
   no known CVEs
   surface: none
A  @open-draft/deferred-promise@2.2.0
   no known CVEs
   surface: none
A  @open-draft/logger@0.3.0
   no known CVEs
   surface: none
A  @open-draft/until@2.1.0
   no known CVEs
   surface: none
A  @openrouter/ai-sdk-provider@0.7.1
   no known CVEs
   surface: none
A  @opentelemetry/api@1.9.0
   no known CVEs
   surface: none
A  @opentelemetry/api-logs@0.209.0
   no known CVEs
   surface: none
A  @opentelemetry/api-logs@0.208.0
   no known CVEs
   surface: none
A  @opentelemetry/api-logs@0.203.0
   no known CVEs
   surface: none
A  @opentelemetry/api-logs@0.57.1
   no known CVEs
   surface: none
A  @opentelemetry/api-logs@0.57.2
   no known CVEs
   surface: none
A  @opentelemetry/context-async-hooks@2.3.0
   no known CVEs
   surface: none
A  @opentelemetry/context-async-hooks@1.30.1
   no known CVEs
   surface: none
A  @opentelemetry/context-async-hooks@2.0.1
   no known CVEs
   surface: none
A  @opentelemetry/exporter-logs-otlp-http@0.203.0
   no known CVEs
   surface: none
A  @opentelemetry/exporter-metrics-otlp-grpc@0.57.1
   no known CVEs
   surface: none
A  @opentelemetry/exporter-metrics-otlp-http@0.57.1
   no known CVEs
   surface: none
A  @opentelemetry/exporter-trace-otlp-http@0.203.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation@0.57.2
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-connect@0.52.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-connect@0.43.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-dataloader@0.26.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-dataloader@0.16.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-express@0.57.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-express@0.47.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-fs@0.28.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-fs@0.19.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-generic-pool@0.52.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-generic-pool@0.43.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-graphql@0.56.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-graphql@0.47.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-hapi@0.45.2
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-ioredis@0.56.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-ioredis@0.47.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-kafkajs@0.18.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-kafkajs@0.7.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-knex@0.53.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-knex@0.44.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-koa@0.57.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-koa@0.47.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-lru-memoizer@0.53.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-lru-memoizer@0.44.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-mongodb@0.61.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-mongodb@0.52.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-mongoose@0.55.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-mongoose@0.46.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-mysql@0.54.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-mysql@0.45.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-mysql2@0.45.2
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-nestjs-core@0.44.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-pg@0.61.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-pg@0.51.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-redis@0.57.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-redis-4@0.46.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-tedious@0.27.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-tedious@0.18.1
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-undici@0.19.0
   no known CVEs
   surface: none
A  @opentelemetry/instrumentation-undici@0.10.1
   no known CVEs
   surface: none
A  @opentelemetry/otlp-grpc-exporter-base@0.57.1
   no known CVEs
   surface: none
A  @opentelemetry/otlp-transformer@0.57.1
   no known CVEs
   surface: none
A  @opentelemetry/otlp-transformer@0.203.0
   no known CVEs
   surface: none
A  @opentelemetry/redis-common@0.38.2
   no known CVEs
   surface: none
A  @opentelemetry/redis-common@0.36.2
   no known CVEs
   surface: none
A  @opentelemetry/sdk-logs@0.203.0
   no known CVEs
   surface: none
A  @opentelemetry/sdk-logs@0.57.1
   no known CVEs
   surface: none
A  @opentelemetry/sdk-metrics@1.30.1
   no known CVEs
   surface: none
A  @opentelemetry/sdk-metrics@2.0.1
   no known CVEs
   surface: none
A  @opentelemetry/sdk-trace-base@1.30.1
   no known CVEs
   surface: none
A  @opentelemetry/sdk-trace-base@2.3.0
   no known CVEs
   surface: none
A  @opentelemetry/sdk-trace-base@2.0.1
   no known CVEs
   surface: none
A  @opentelemetry/sdk-trace-node@2.0.1
   no known CVEs
   surface: none
A  @opentelemetry/sdk-trace-web@2.0.1
   no known CVEs
   surface: none
A  @opentelemetry/sql-common@0.41.2
   no known CVEs
   surface: none
A  @opentelemetry/sql-common@0.40.1
   no known CVEs
   surface: none
A  @otplib/core@12.0.1
   no known CVEs
   surface: none
A  @otplib/plugin-crypto@12.0.1
   no known CVEs
   surface: none
A  @otplib/plugin-thirty-two@12.0.1
   no known CVEs
   surface: none
A  @otplib/preset-default@12.0.1
   no known CVEs
   surface: none
A  @otplib/preset-v11@12.0.1
   no known CVEs
   surface: none
A  @pagefind/darwin-arm64@1.5.2
   no known CVEs
   surface: none
A  @panva/hkdf@1.0.4
   no known CVEs
   surface: none
A  @paralleldrive/cuid2@2.3.1
   no known CVEs
   surface: none
A  @paralleldrive/cuid2@2.2.2
   no known CVEs
   surface: none
A  @pkgjs/parseargs@0.11.0
   no known CVEs
   surface: none
A  @polka/url@0.5.0
   no known CVEs
   surface: none
A  @polka/url@1.0.0-next.25
   no known CVEs
   surface: none
A  @prisma/adapter-pg@6.16.1
   no known CVEs
   surface: none
A  @prisma/config@6.15.0
   no known CVEs
   surface: none
A  @prisma/config@6.16.1
   no known CVEs
   surface: none
A  @prisma/config@6.19.1
   no known CVEs
   surface: none
A  @prisma/config@6.16.2
   no known CVEs
   surface: none
A  @prisma/debug@5.22.0
   no known CVEs
   surface: none
A  @prisma/debug@6.15.0
   no known CVEs
   surface: none
A  @prisma/debug@6.16.1
   no known CVEs
   surface: none
A  @prisma/debug@6.16.2
   no known CVEs
   surface: none
A  @prisma/dmmf@6.15.0
   no known CVEs
   surface: none
A  @prisma/dmmf@6.16.2
   no known CVEs
   surface: none
A  @prisma/driver-adapter-utils@6.15.0
   no known CVEs
   surface: none
A  @prisma/driver-adapter-utils@6.16.2
   no known CVEs
   surface: none
A  @prisma/driver-adapter-utils@6.16.1
   no known CVEs
   surface: none
A  @prisma/engines-version@5.22.0-44.605197351a3c8bdd595af2d2a9bc3025bca48ea2
   no known CVEs
   surface: none
A  @prisma/engines-version@6.15.0-5.85179d7826409ee107a6ba334b5e305ae3fba9fb
   no known CVEs
   surface: none
A  @prisma/engines-version@6.16.0-7.1c57fdcd7e44b29b9313256c76699e91c3ac3c43
   no known CVEs
   surface: none
A  @prisma/generator@6.15.0
   no known CVEs
   surface: none
A  @prisma/generator@6.16.2
   no known CVEs
   surface: none
A  @prisma/instrumentation@6.19.0
   no known CVEs
   surface: none
A  @prisma/instrumentation@6.11.1
   no known CVEs
   surface: none
A  @prisma/nextjs-monorepo-workaround-plugin@6.16.1
   no known CVEs
   surface: none
A  @prisma/schema-files-loader@5.22.0
   no known CVEs
   surface: none
A  @prisma/schema-files-loader@6.15.0
   no known CVEs
   surface: none
A  @prisma/schema-files-loader@6.16.2
   no known CVEs
   surface: none
A  @protobuf-ts/runtime@2.11.1
   no known CVEs
   surface: none
A  @protobufjs/aspromise@1.1.2
   no known CVEs
   surface: none
A  @protobufjs/base64@1.1.2
   no known CVEs
   surface: none
A  @protobufjs/codegen@2.0.4
   no known CVEs
   surface: none
A  @protobufjs/eventemitter@1.1.0
   no known CVEs
   surface: none
A  @protobufjs/float@1.0.2
   no known CVEs
   surface: none
A  @protobufjs/path@1.1.2
   no known CVEs
   surface: none
A  @protobufjs/pool@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/number@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/number@0.1.0
   no known CVEs
   surface: none
A  @radix-ui/primitive@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/primitive@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/primitive@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/primitive@1.1.1
   no known CVEs
   surface: none
A  @radix-ui/primitive@0.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-arrow@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-avatar@1.1.3
   no known CVEs
   surface: none
A  @radix-ui/react-checkbox@1.0.4
   no known CVEs
   surface: none
A  @radix-ui/react-collapsible@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-collection@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-collection@1.1.1
   no known CVEs
   surface: none
A  @radix-ui/react-collection@0.1.4
   no known CVEs
   surface: none
A  @radix-ui/react-compose-refs@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-compose-refs@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-compose-refs@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-compose-refs@1.1.1
   no known CVEs
   surface: none
A  @radix-ui/react-compose-refs@0.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-context@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-context@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-context@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-context@1.1.1
   no known CVEs
   surface: none
A  @radix-ui/react-context@0.1.1
   no known CVEs
   surface: none
A  @radix-ui/react-dialog@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-dialog@1.0.4
   no known CVEs
   surface: none
A  @radix-ui/react-direction@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-direction@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-dismissable-layer@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-dismissable-layer@1.0.4
   no known CVEs
   surface: none
A  @radix-ui/react-dismissable-layer@1.0.5
   no known CVEs
   surface: none
A  @radix-ui/react-dismissable-layer@0.1.5
   no known CVEs
   surface: none
A  @radix-ui/react-dropdown-menu@2.0.5
   no known CVEs
   surface: none
A  @radix-ui/react-focus-guards@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-focus-guards@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-focus-scope@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-focus-scope@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-focus-scope@0.1.4
   no known CVEs
   surface: none
A  @radix-ui/react-hover-card@1.0.7
   no known CVEs
   surface: none
A  @radix-ui/react-id@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-id@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-id@0.1.5
   no known CVEs
   surface: none
A  @radix-ui/react-label@0.1.5
   no known CVEs
   surface: none
A  @radix-ui/react-menu@2.0.5
   no known CVEs
   surface: none
A  @radix-ui/react-popover@1.0.6
   no known CVEs
   surface: none
A  @radix-ui/react-popper@1.1.2
   no known CVEs
   surface: none
A  @radix-ui/react-popper@1.1.3
   no known CVEs
   surface: none
A  @radix-ui/react-portal@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-portal@1.0.4
   no known CVEs
   surface: none
A  @radix-ui/react-portal@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-portal@0.1.4
   no known CVEs
   surface: none
A  @radix-ui/react-presence@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-presence@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-primitive@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-primitive@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-primitive@2.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-primitive@2.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-primitive@0.1.4
   no known CVEs
   surface: none
A  @radix-ui/react-primitive@2.0.2
   no known CVEs
   surface: none
A  @radix-ui/react-radio-group@1.1.3
   no known CVEs
   surface: none
A  @radix-ui/react-roving-focus@1.0.4
   no known CVEs
   surface: none
A  @radix-ui/react-select@0.1.1
   no known CVEs
   surface: none
A  @radix-ui/react-slider@1.2.2
   no known CVEs
   surface: none
A  @radix-ui/react-slot@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-slot@1.1.2
   no known CVEs
   surface: none
A  @radix-ui/react-slot@1.0.2
   no known CVEs
   surface: none
A  @radix-ui/react-slot@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-slot@1.1.1
   no known CVEs
   surface: none
A  @radix-ui/react-slot@0.1.2
   no known CVEs
   surface: none
A  @radix-ui/react-switch@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-toast@1.1.5
   no known CVEs
   surface: none
A  @radix-ui/react-toggle@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-toggle-group@1.0.4
   no known CVEs
   surface: none
A  @radix-ui/react-tooltip@1.0.6
   no known CVEs
   surface: none
A  @radix-ui/react-use-body-pointer-events@0.1.1
   no known CVEs
   surface: none
A  @radix-ui/react-use-callback-ref@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-callback-ref@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-use-callback-ref@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-callback-ref@0.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-controllable-state@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-controllable-state@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-use-controllable-state@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-controllable-state@0.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-escape-keydown@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-escape-keydown@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-use-escape-keydown@0.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-layout-effect@1.0.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-layout-effect@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-use-layout-effect@0.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-layout-effect@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-previous@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-use-previous@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-use-previous@0.1.1
   no known CVEs
   surface: none
A  @radix-ui/react-use-rect@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-use-size@1.0.1
   no known CVEs
   surface: none
A  @radix-ui/react-use-size@1.1.0
   no known CVEs
   surface: none
A  @radix-ui/react-visually-hidden@1.0.3
   no known CVEs
   surface: none
A  @radix-ui/react-visually-hidden@0.1.4
   no known CVEs
   surface: none
A  @radix-ui/rect@1.0.1
   no known CVEs
   surface: none
A  @reach/observe-rect@1.2.0
   no known CVEs
   surface: none
A  @reach/portal@0.16.2
   no known CVEs
   surface: none
A  @reach/utils@0.16.0
   no known CVEs
   surface: none
A  @react-stately/flags@3.1.2
   no known CVEs
   surface: none
A  @redis/bloom@1.2.0
   no known CVEs
   surface: none
A  @redis/graph@1.1.1
   no known CVEs
   surface: none
A  @redis/json@1.0.7
   no known CVEs
   surface: none
A  @redis/search@1.2.0
   no known CVEs
   surface: none
A  @redis/time-series@1.1.0
   no known CVEs
   surface: none
A  @repeaterjs/repeater@3.0.6
   no known CVEs
   surface: none
A  @rolldown/pluginutils@1.0.0-beta.47
   no known CVEs
   surface: none
A  @rolldown/pluginutils@1.0.0-beta.53
   no known CVEs
   surface: none
A  @rollup/plugin-node-resolve@15.0.1
   no known CVEs
   surface: none
A  @rollup/pluginutils@5.3.0
   no known CVEs
   surface: none
A  @rollup/pluginutils@5.1.0
   no known CVEs
   surface: none
A  @rushstack/problem-matcher@0.1.1
   no known CVEs
   surface: none
A  @rushstack/rig-package@0.6.0
   no known CVEs
   surface: none
A  @rushstack/terminal@0.19.5
   no known CVEs
   surface: none
A  @rushstack/ts-command-line@5.1.5
   no known CVEs
   surface: none
A  @scure/base@1.1.1
   no known CVEs
   surface: none
A  @scure/base@1.1.3
   no known CVEs
   surface: none
A  @scure/bip32@1.3.1
   no known CVEs
   surface: none
A  @scure/bip39@1.2.1
   no known CVEs
   surface: none
A  @sec-ant/readable-stream@0.4.1
   no known CVEs
   surface: none
A  @sendgrid/client@7.7.0
   no known CVEs
   surface: none
A  @sendgrid/helpers@7.7.0
   no known CVEs
   surface: none
A  @sentry-internal/feedback@8.55.0
   no known CVEs
   surface: none
A  @sentry-internal/feedback@10.33.0
   no known CVEs
   surface: none
A  @sentry-internal/replay-canvas@8.55.0
   no known CVEs
   surface: none
A  @sentry-internal/replay-canvas@10.33.0
   no known CVEs
   surface: none
A  @sentry/babel-plugin-component-annotate@4.6.1
   no known CVEs
   surface: none
A  @sentry/cli-darwin@2.58.4
   no known CVEs
   surface: none
A  @sentry/node@9.46.0
   no known CVEs
   surface: none
A  @sentry/react@10.33.0
   no known CVEs
   surface: none
A  @sentry/webpack-plugin@4.6.1
   no known CVEs
   surface: none
A  @shikijs/core@3.23.0
   no known CVEs
   surface: none
A  @shikijs/engine-javascript@3.23.0
   no known CVEs
   surface: none
A  @shikijs/themes@3.23.0
   no known CVEs
   surface: none
A  @shikijs/twoslash@3.23.0
   no known CVEs
   surface: none
A  @shikijs/types@3.23.0
   no known CVEs
   surface: none
A  @shikijs/vscode-textmate@10.0.2
   no known CVEs
   surface: none
A  @sinclair/typebox@0.27.8
   no known CVEs
   surface: none
A  @sindresorhus/is@4.6.0
   no known CVEs
   surface: none
A  @sindresorhus/merge-streams@4.0.0
   no known CVEs
   surface: none
A  @sinonjs/fake-timers@10.3.0
   no known CVEs
   surface: none
A  @smithy/abort-controller@4.0.5
   no known CVEs
   surface: none
A  @smithy/hash-node@4.0.5
   no known CVEs
   surface: none
A  @smithy/invalid-dependency@4.0.5
   no known CVEs
   surface: none
A  @smithy/is-array-buffer@4.0.0
   no known CVEs
   surface: none
A  @smithy/is-array-buffer@2.2.0
   no known CVEs
   surface: none
A  @smithy/middleware-content-length@4.0.5
   no known CVEs
   surface: none
A  @smithy/middleware-endpoint@4.1.18
   no known CVEs
   surface: none
A  @smithy/middleware-retry@4.1.19
   no known CVEs
   surface: none
A  @smithy/middleware-serde@4.0.9
   no known CVEs
   surface: none
A  @smithy/middleware-stack@4.0.5
   no known CVEs
   surface: none
A  @smithy/node-config-provider@4.1.4
   no known CVEs
   surface: none
A  @smithy/property-provider@4.0.5
   no known CVEs
   surface: none
A  @smithy/protocol-http@5.1.3
   no known CVEs
   surface: none
A  @smithy/querystring-builder@4.0.5
   no known CVEs
   surface: none
A  @smithy/querystring-parser@4.0.5
   no known CVEs
   surface: none
A  @smithy/service-error-classification@4.0.7
   no known CVEs
   surface: none
A  @smithy/shared-ini-file-loader@4.0.5
   no known CVEs
   surface: none
A  @smithy/signature-v4@5.1.3
   no known CVEs
   surface: none
A  @smithy/smithy-client@4.4.10
   no known CVEs
   surface: none
A  @smithy/url-parser@4.0.5
   no known CVEs
   surface: none
A  @smithy/util-base64@4.0.0
   no known CVEs
   surface: none
A  @smithy/util-body-length-browser@4.0.0
   no known CVEs
   surface: none
A  @smithy/util-body-length-node@4.0.0
   no known CVEs
   surface: none
A  @smithy/util-buffer-from@4.0.0
   no known CVEs
   surface: none
A  @smithy/util-buffer-from@2.2.0
   no known CVEs
   surface: none
A  @smithy/util-config-provider@4.0.0
   no known CVEs
   surface: none
A  @smithy/util-defaults-mode-browser@4.0.26
   no known CVEs
   surface: none
A  @smithy/util-defaults-mode-node@4.0.26
   no known CVEs
   surface: none
A  @smithy/util-endpoints@3.0.7
   no known CVEs
   surface: none
A  @smithy/util-hex-encoding@4.0.0
   no known CVEs
   surface: none
A  @smithy/util-middleware@4.0.5
   no known CVEs
   surface: none
A  @smithy/util-retry@4.0.7
   no known CVEs
   surface: none
A  @smithy/util-stream@4.2.4
   no known CVEs
   surface: none
A  @smithy/util-uri-escape@4.0.0
   no known CVEs
   surface: none
A  @smithy/util-utf8@4.0.0
   no known CVEs
   surface: none
A  @smithy/util-utf8@2.3.0
   no known CVEs
   surface: none
A  @smithy/util-waiter@4.0.7
   no known CVEs
   surface: none
A  @socket.io/component-emitter@3.1.2
   no known CVEs
   surface: none
A  @sodaru/yup-to-json-schema@2.0.1
   no known CVEs
   surface: none
A  @sqltools/formatter@1.2.5
   no known CVEs
   surface: none
A  @stablelib/base64@1.0.1
   no known CVEs
   surface: none
A  @standard-schema/spec@1.0.0
   no known CVEs
   surface: none
A  @standard-schema/utils@0.3.0
   no known CVEs
   surface: none
A  @stripe/react-stripe-js@1.10.0
   no known CVEs
   surface: none
A  @swc/counter@0.1.3
   no known CVEs
   surface: none
A  @swc/types@0.1.25
   no known CVEs
   surface: none
A  @tailwindcss/postcss@4.1.15
   no known CVEs
   surface: none
A  @tailwindcss/typography@0.5.4
   no known CVEs
   surface: none
A  @tanstack/react-table@8.20.6
   no known CVEs
   surface: none
A  @tanstack/react-virtual@3.10.9
   no known CVEs
   surface: none
A  @tanstack/table-core@8.20.5
   no known CVEs
   surface: none
A  @tanstack/virtual-core@3.13.23
   no known CVEs
   surface: none
A  @tanstack/virtual-core@3.10.9
   no known CVEs
   surface: none
A  @tediousjs/connection-string@0.5.0
   no known CVEs
   surface: none
A  @testing-library/dom@8.17.1
   no known CVEs
   surface: none
A  @testing-library/jest-dom@5.17.0
   no known CVEs
   surface: none
A  @testing-library/react@16.0.1
   no known CVEs
   surface: none
A  @testing-library/user-event@14.6.1
   no known CVEs
   surface: none
A  @theguild/remark-npm2yarn@0.3.3
   no known CVEs
   surface: none
A  @todesktop/client-core@1.20.0
   no known CVEs
   surface: none
A  @todesktop/client-electron-types@28.0.0
   no known CVEs
   surface: none
A  @todesktop/client-electron-updater-types@5.3.0
   no known CVEs
   surface: none
A  @todesktop/client-todesktop-runtime-types@1.5.7-beta.2
   no known CVEs
   surface: none
A  @todesktop/client-todesktop-runtime-types@1.5.7
   no known CVEs
   surface: none
A  @todesktop/client-util@1.4.0
   no known CVEs
   surface: none
A  @todesktop/tailwind-variants@1.0.1
   no known CVEs
   surface: none
A  @tokenizer/inflate@0.2.7
   no known CVEs
   surface: none
A  @tokenizer/token@0.3.0
   no known CVEs
   surface: none
A  @trigger.dev/schema-to-json@4.3.2
   no known CVEs
   surface: none
A  @tryvital/vital-node@1.4.6
   no known CVEs
   surface: none
A  @tsconfig/node10@1.0.8
   no known CVEs
   surface: none
A  @tsconfig/node12@1.0.9
   no known CVEs
   surface: none
A  @tsconfig/node14@1.0.1
   no known CVEs
   surface: none
A  @tsconfig/node16@1.0.2
   no known CVEs
   surface: none
A  @types/accept-language-parser@1.5.2
   no known CVEs
   surface: none
A  @types/argparse@1.0.38
   no known CVEs
   surface: none
A  @types/aria-query@4.2.2
   no known CVEs
   surface: none
A  @types/async@3.2.15
   no known CVEs
   surface: none
A  @types/aws-lambda@8.10.152
   no known CVEs
   surface: none
A  @types/babel__core@7.20.5
   no known CVEs
   surface: none
A  @types/babel__generator@7.6.7
   no known CVEs
   surface: none
A  @types/babel__template@7.4.4
   no known CVEs
   surface: none
A  @types/babel__traverse@7.20.5
   no known CVEs
   surface: none
A  @types/backblaze-b2@1.5.6
   no known CVEs
   surface: none
A  @types/bcryptjs@2.4.2
   no known CVEs
   surface: none
A  @types/body-parser@1.19.2
   no known CVEs
   surface: none
A  @types/chai@5.2.3
   no known CVEs
   surface: none
A  @types/cli-progress@3.11.4
   no known CVEs
   surface: none
A  @types/connect@3.4.38
   no known CVEs
   surface: none
A  @types/cookie@0.4.1
   no known CVEs
   surface: none
A  @types/cookie@0.6.0
   no known CVEs
   surface: none
A  @types/cookie-parser@1.4.7
   no known CVEs
   surface: none
A  @types/cookiejar@2.1.5
   no known CVEs
   surface: none
A  @types/cors@2.8.19
   no known CVEs
   surface: none
A  @types/d3@7.4.3
   no known CVEs
   surface: none
A  @types/d3-array@3.0.4
   no known CVEs
   surface: none
A  @types/d3-array@3.2.2
   no known CVEs
   surface: none
A  @types/d3-axis@3.0.6
   no known CVEs
   surface: none
A  @types/d3-brush@3.0.6
   no known CVEs
   surface: none
A  @types/d3-chord@3.0.6
   no known CVEs
   surface: none
A  @types/d3-color@3.1.0
   no known CVEs
   surface: none
A  @types/d3-contour@3.0.6
   no known CVEs
   surface: none
A  @types/d3-delaunay@6.0.4
   no known CVEs
   surface: none
A  @types/d3-dispatch@3.0.7
   no known CVEs
   surface: none
A  @types/d3-drag@3.0.7
   no known CVEs
   surface: none
A  @types/d3-dsv@3.0.7
   no known CVEs
   surface: none
A  @types/d3-ease@3.0.0
   no known CVEs
   surface: none
A  @types/d3-ease@3.0.2
   no known CVEs
   surface: none
A  @types/d3-fetch@3.0.7
   no known CVEs
   surface: none
A  @types/d3-force@3.0.10
   no known CVEs
   surface: none
A  @types/d3-format@3.0.4
   no known CVEs
   surface: none
A  @types/d3-geo@3.1.0
   no known CVEs
   surface: none
A  @types/d3-hierarchy@3.1.7
   no known CVEs
   surface: none
A  @types/d3-interpolate@3.0.1
   no known CVEs
   surface: none
A  @types/d3-interpolate@3.0.4
   no known CVEs
   surface: none
A  @types/d3-path@3.0.0
   no known CVEs
   surface: none
A  @types/d3-polygon@3.0.2
   no known CVEs
   surface: none
A  @types/d3-quadtree@3.0.6
   no known CVEs
   surface: none
A  @types/d3-random@3.0.3
   no known CVEs
   surface: none
A  @types/d3-scale@4.0.3
   no known CVEs
   surface: none
A  @types/d3-scale@4.0.9
   no known CVEs
   surface: none
A  @types/d3-scale-chromatic@3.1.0
   no known CVEs
   surface: none
A  @types/d3-selection@3.0.11
   no known CVEs
   surface: none
A  @types/d3-shape@3.1.1
   no known CVEs
   surface: none
A  @types/d3-shape@3.1.8
   no known CVEs
   surface: none
A  @types/d3-time@3.0.0
   no known CVEs
   surface: none
A  @types/d3-time-format@4.0.3
   no known CVEs
   surface: none
A  @types/d3-timer@3.0.0
   no known CVEs
   surface: none
A  @types/d3-timer@3.0.2
   no known CVEs
   surface: none
A  @types/d3-transition@3.0.9
   no known CVEs
   surface: none
A  @types/d3-zoom@3.0.8
   no known CVEs
   surface: none
A  @types/deasync@0.1.5
   no known CVEs
   surface: none
A  @types/debug@4.1.12
   no known CVEs
   surface: none
A  @types/deep-eql@4.0.2
   no known CVEs
   surface: none
A  @types/detect-port@1.3.2
   no known CVEs
   surface: none
A  @types/dompurify@3.0.5
   no known CVEs
   surface: none
A  @types/ejs@3.1.5
   no known CVEs
   surface: none
A  @types/eslint@9.6.1
   no known CVEs
   surface: none
A  @types/eslint-scope@3.7.7
   no known CVEs
   surface: none
A  @types/estree@1.0.8
   no known CVEs
   surface: none
A  @types/estree-jsx@1.0.5
   no known CVEs
   surface: none
A  @types/express@4.17.21
   no known CVEs
   surface: none
A  @types/express-jwt@0.0.42
   no known CVEs
   surface: none
A  @types/express-serve-static-core@4.17.41
   no known CVEs
   surface: none
A  @types/express-unless@0.5.3
   no known CVEs
   surface: none
A  @types/fs-extra@11.0.4
   no known CVEs
   surface: none
A  @types/geojson@7946.0.16
   no known CVEs
   surface: none
A  @types/glidejs__glide@3.4.2
   no known CVEs
   surface: none
A  @types/graceful-fs@4.1.9
   no known CVEs
   surface: none
A  @types/graphql@0.13.4
   no known CVEs
   surface: none
A  @types/hast@3.0.4
   no known CVEs
   surface: none
A  @types/hoist-non-react-statics@3.3.6
   no known CVEs
   surface: none
A  @types/http-proxy@1.17.14
   no known CVEs
   surface: none
A  @types/istanbul-lib-coverage@2.0.4
   no known CVEs
   surface: none
A  @types/istanbul-lib-report@3.0.0
   no known CVEs
   surface: none
A  @types/istanbul-reports@3.0.1
   no known CVEs
   surface: none
A  @types/jest@29.5.12
   no known CVEs
   surface: none
A  @types/js-cookie@2.2.7
   no known CVEs
   surface: none
A  @types/js-yaml@4.0.9
   no known CVEs
   surface: none
A  @types/jsdom@21.1.7
   no known CVEs
   surface: none
A  @types/json-schema@7.0.15
   no known CVEs
   surface: none
A  @types/jsonfile@6.1.4
   no known CVEs
   surface: none
A  @types/jsonwebtoken@9.0.5
   no known CVEs
   surface: none
A  @types/jsonwebtoken@9.0.6
   no known CVEs
   surface: none
A  @types/katex@0.16.8
   no known CVEs
   surface: none
A  @types/linkify-it@3.0.5
   no known CVEs
   surface: none
A  @types/linkify-it@5.0.0
   no known CVEs
   surface: none
A  @types/lodash@4.14.182
   no known CVEs
   surface: none
A  @types/luxon@3.4.2
   no known CVEs
   surface: none
A  @types/markdown-it@12.2.3
   no known CVEs
   surface: none
A  @types/markdown-it@14.1.2
   no known CVEs
   surface: none
A  @types/md5@2.3.2
   no known CVEs
   surface: none
A  @types/mdast@4.0.4
   no known CVEs
   surface: none
A  @types/mdurl@1.0.2
   no known CVEs
   surface: none
A  @types/mdurl@2.0.0
   no known CVEs
   surface: none
A  @types/mdx@2.0.13
   no known CVEs
   surface: none
A  @types/memory-cache@0.2.2
   no known CVEs
   surface: none
A  @types/methods@1.1.4
   no known CVEs
   surface: none
A  @types/micro@7.3.7
   no known CVEs
   surface: none
A  @types/mime@1.3.2
   no known CVEs
   surface: none
A  @types/minimist@1.2.2
   no known CVEs
   surface: none
A  @types/module-alias@2.0.1
   no known CVEs
   surface: none
A  @types/ms@0.7.31
   no known CVEs
   surface: none
A  @types/mysql@2.15.26
   no known CVEs
   surface: none
A  @types/mysql@2.15.27
   no known CVEs
   surface: none
A  @types/nlcst@2.0.3
   no known CVEs
   surface: none
A  @types/node@20.17.23
   no known CVEs
   surface: none
A  @types/node-fetch@2.6.12
   no known CVEs
   surface: none
A  @types/node-schedule@2.1.0
   no known CVEs
   surface: none
A  @types/nodemailer@6.4.5
   no known CVEs
   surface: none
A  @types/normalize-package-data@2.4.1
   no known CVEs
   surface: none
A  @types/parse-json@4.0.0
   no known CVEs
   surface: none
A  @types/passport@1.0.16
   no known CVEs
   surface: none
A  @types/passport-jwt@3.0.13
   no known CVEs
   surface: none
A  @types/passport-strategy@0.2.38
   no known CVEs
   surface: none
A  @types/pg@8.11.14
   no known CVEs
   surface: none
A  @types/pg@8.15.6
   no known CVEs
   surface: none
A  @types/pg@8.6.1
   no known CVEs
   surface: none
A  @types/pg-pool@2.0.6
   no known CVEs
   surface: none
A  @types/prismjs@1.26.5
   no known CVEs
   surface: none
A  @types/prop-types@15.7.5
   no known CVEs
   surface: none
A  @types/qrcode@1.4.3
   no known CVEs
   surface: none
A  @types/qs@6.9.7
   no known CVEs
   surface: none
A  @types/range-parser@1.2.4
   no known CVEs
   surface: none
A  @types/react@18.0.26
   no known CVEs
   surface: none
A  @types/react-calendar@3.5.0
   no known CVEs
   surface: none
A  @types/react-dom@18.2.6
   no known CVEs
   surface: none
A  @types/react-transition-group@4.4.4
   no known CVEs
   surface: none
A  @types/readable-stream@4.0.18
   no known CVEs
   surface: none
A  @types/remove-markdown@0.3.1
   no known CVEs
   surface: none
A  @types/resolve@1.20.2
   no known CVEs
   surface: none
A  @types/retry@0.12.2
   no known CVEs
   surface: none
A  @types/sanitize-html@2.9.0
   no known CVEs
   surface: none
A  @types/scheduler@0.16.2
   no known CVEs
   surface: none
A  @types/send@0.17.4
   no known CVEs
   surface: none
A  @types/serve-static@1.13.10
   no known CVEs
   surface: none
A  @types/shimmer@1.2.0
   no known CVEs
   surface: none
A  @types/stack-utils@2.0.1
   no known CVEs
   surface: none
A  @types/statuses@2.0.5
   no known CVEs
   surface: none
A  @types/stripe@8.0.417
   no known CVEs
   surface: none
A  @types/superagent@8.1.4
   no known CVEs
   surface: none
A  @types/supertest@2.0.16
   no known CVEs
   surface: none
A  @types/tedious@4.0.14
   no known CVEs
   surface: none
A  @types/testing-library__jest-dom@5.14.8
   no known CVEs
   surface: none
A  @types/tinycolor2@1.4.3
   no known CVEs
   surface: none
A  @types/tough-cookie@4.0.5
   no known CVEs
   surface: none
A  @types/triple-beam@1.3.5
   no known CVEs
   surface: none
A  @types/trusted-types@2.0.7
   no known CVEs
   surface: none
A  @types/turndown@5.0.1
   no known CVEs
   surface: none
A  @types/unist@2.0.11
   no known CVEs
   surface: none
A  @types/unist@3.0.3
   no known CVEs
   surface: none
A  @types/use-sync-external-store@0.0.6
   no known CVEs
   surface: none
A  @types/uuid@8.3.1
   no known CVEs
   surface: none
A  @types/uuid@9.0.8
   no known CVEs
   surface: none
A  @types/validator@13.15.10
   no known CVEs
   surface: none
A  @types/web-push@3.6.3
   no known CVEs
   surface: none
A  @types/webidl-conversions@6.1.1
   no known CVEs
   surface: none
A  @types/whatwg-url@11.0.4
   no known CVEs
   surface: none
A  @types/yargs@17.0.24
   no known CVEs
   surface: none
A  @types/yargs-parser@21.0.0
   no known CVEs
   surface: none
A  @types/yoga-layout@1.9.2
   no known CVEs
   surface: none
A  @typescript-eslint/types@6.7.2
   no known CVEs
   surface: none
A  @typescript-eslint/visitor-keys@6.7.2
   no known CVEs
   surface: none
A  @ungap/structured-clone@1.3.0
   no known CVEs
   surface: none
A  @unkey/ratelimit@2.1.3
   no known CVEs
   surface: none
A  @upsetjs/venn.js@2.0.0
   no known CVEs
   surface: none
A  @urql/core@5.1.1
   no known CVEs
   surface: none
A  @urql/exchange-retry@2.0.0
   no known CVEs
   surface: none
A  @vercel/functions@1.4.0
   no known CVEs
   surface: none
A  @vitest/expect@4.0.16
   no known CVEs
   surface: none
A  @vitest/pretty-format@4.0.16
   no known CVEs
   surface: none
A  @vitest/runner@4.0.16
   no known CVEs
   surface: none
A  @vitest/spy@4.0.16
   no known CVEs
   surface: none
A  @vitest/utils@4.0.16
   no known CVEs
   surface: none
A  @volar/language-core@2.4.27
   no known CVEs
   surface: none
A  @volar/source-map@2.4.27
   no known CVEs
   surface: none
A  @vue/shared@3.5.26
   no known CVEs
   surface: none
A  @webassemblyjs/ast@1.14.1
   no known CVEs
   surface: none
A  @webassemblyjs/floating-point-hex-parser@1.13.2
   no known CVEs
   surface: none
A  @webassemblyjs/helper-api-error@1.13.2
   no known CVEs
   surface: none
A  @webassemblyjs/helper-buffer@1.14.1
   no known CVEs
   surface: none
A  @webassemblyjs/helper-numbers@1.13.2
   no known CVEs
   surface: none
A  @webassemblyjs/helper-wasm-bytecode@1.13.2
   no known CVEs
   surface: none
A  @webassemblyjs/helper-wasm-section@1.14.1
   no known CVEs
   surface: none
A  @webassemblyjs/ieee754@1.13.2
   no known CVEs
   surface: none
A  @webassemblyjs/leb128@1.13.2
   no known CVEs
   surface: none
A  @webassemblyjs/utf8@1.13.2
   no known CVEs
   surface: none
A  @webassemblyjs/wasm-edit@1.14.1
   no known CVEs
   surface: none
A  @webassemblyjs/wasm-gen@1.14.1
   no known CVEs
   surface: none
A  @webassemblyjs/wasm-opt@1.14.1
   no known CVEs
   surface: none
A  @webassemblyjs/wasm-parser@1.14.1
   no known CVEs
   surface: none
A  @webassemblyjs/wast-printer@1.14.1
   no known CVEs
   surface: none
A  @webbtc/webln-types@3.0.0
   no known CVEs
   surface: none
A  @whatwg-node/disposablestack@0.0.6
   no known CVEs
   surface: none
A  @whatwg-node/promise-helpers@1.3.0
   no known CVEs
   surface: none
A  @wojtekmaj/date-utils@1.0.3
   no known CVEs
   surface: none
A  @wojtekmaj/react-daterange-picker@3.4.0
   no known CVEs
   surface: none
A  @xmldom/is-dom-node@1.0.1
   no known CVEs
   surface: none
A  @xobotyi/scrollbar-width@1.9.5
   no known CVEs
   surface: none
A  @xtuc/ieee754@1.2.0
   no known CVEs
   surface: none
A  @xtuc/long@4.2.2
   no known CVEs
   surface: none
A  abab@2.0.6
   no known CVEs
   surface: none
A  abbrev@1.1.1
   no known CVEs
   surface: none
A  abbrev@2.0.0
   no known CVEs
   surface: none
A  abort-controller@3.0.0
   no known CVEs
   surface: none
A  accept-language-parser@1.5.0
   no known CVEs
   surface: none
A  accepts@1.3.8
   no known CVEs
   surface: none
A  accepts@2.0.0
   no known CVEs
   surface: none
A  acorn-import-attributes@1.9.5
   no known CVEs
   surface: none
A  acorn-import-phases@1.0.4
   no known CVEs
   surface: none
A  acorn-jsx@5.3.2
   no known CVEs
   surface: none
A  acorn-walk@8.2.0
   no known CVEs
   surface: none
A  aggregate-error@3.1.0
   no known CVEs
   surface: none
A  ajv-draft-04@1.0.0
   no known CVEs
   surface: none
A  ajv-formats@2.1.1
   no known CVEs
   surface: none
A  ajv-formats@3.0.1
   no known CVEs
   surface: none
A  ajv-keywords@5.1.0
   no known CVEs
   surface: none
A  ajv-keywords@3.5.2
   no known CVEs
   surface: none
A  alien-signals@0.4.14
   no known CVEs
   surface: none
A  ansi-colors@4.1.3
   no known CVEs
   surface: none
A  ansi-escapes@4.3.2
   no known CVEs
   surface: none
A  ansi-escapes@7.0.0
   no known CVEs
   surface: none
A  ansi-escapes@6.2.1
   no known CVEs
   surface: none
A  ansi-regex@5.0.1
   no known CVEs
   surface: none
A  ansi-regex@6.0.1
   no known CVEs
   surface: none
A  ansi-styles@4.3.0
   no known CVEs
   surface: none
A  ansi-styles@5.2.0
   no known CVEs
   surface: none
A  ansi-styles@3.2.1
   no known CVEs
   surface: none
A  ansi-styles@6.2.1
   no known CVEs
   surface: none
A  ansicolors@0.3.2
   no known CVEs
   surface: none
A  ansis@3.17.0
   no known CVEs
   surface: none
A  any-base@1.1.0
   no known CVEs
   surface: none
A  anymatch@3.1.2
   no known CVEs
   surface: none
A  append-field@1.0.0
   no known CVEs
   surface: none
A  aproba@2.0.0
   no known CVEs
   surface: none
A  are-we-there-yet@3.0.1
   no known CVEs
   surface: none
A  arg@5.0.2
   no known CVEs
   surface: none
A  arg@4.1.3
   no known CVEs
   surface: none
A  arg@4.1.0
   no known CVEs
   surface: none
A  argparse@1.0.10
   no known CVEs
   surface: none
A  aria-hidden@1.1.3
   no known CVEs
   surface: none
A  aria-query@5.3.0
   no known CVEs
   surface: none
A  arr-rotate@1.0.0
   no known CVEs
   surface: none
A  array-buffer-byte-length@1.0.2
   no known CVEs
   surface: none
A  array-flatten@1.1.1
   no known CVEs
   surface: none
A  array-iterate@2.0.1
   no known CVEs
   surface: none
A  array-timsort@1.0.3
   no known CVEs
   surface: none
A  array-union@2.1.0
   no known CVEs
   surface: none
A  arraybuffer.prototype.slice@1.0.4
   no known CVEs
   surface: none
A  arrify@2.0.1
   no known CVEs
   surface: none
A  arrify@1.0.1
   no known CVEs
   surface: none
A  asap@2.0.6
   no known CVEs
   surface: none
A  asn1.js@5.4.1
   no known CVEs
   surface: none
A  assertion-error@2.0.1
   no known CVEs
   surface: none
A  ast-v8-to-istanbul@0.3.12
   no known CVEs
   surface: none
A  astral-regex@2.0.0
   no known CVEs
   surface: none
A  async-scheduler@1.4.4
   no known CVEs
   surface: none
A  asynckit@0.4.0
   no known CVEs
   surface: none
A  at-least-node@1.0.0
   no known CVEs
   surface: none
A  auth0@2.40.0
   no known CVEs
   surface: none
A  auto-bind@4.0.0
   no known CVEs
   surface: none
A  auto-bind@5.0.1
   no known CVEs
   surface: none
A  available-typed-arrays@1.0.7
   no known CVEs
   surface: none
A  aws-ssl-profiles@1.1.2
   no known CVEs
   surface: none
A  axios-retry@4.5.0
   no known CVEs
   surface: none
A  axios-retry@3.2.4
   no known CVEs
   surface: none
A  babel-jest@29.7.0
   no known CVEs
   surface: none
A  babel-plugin-jest-hoist@29.6.3
   no known CVEs
   surface: none
A  babel-plugin-macros@2.8.0
   no known CVEs
   surface: none
A  babel-preset-current-node-syntax@1.0.1
   no known CVEs
   surface: none
A  babel-preset-jest@29.6.3
   no known CVEs
   surface: none
A  backblaze-b2@1.7.1
   no known CVEs
   surface: none
A  bail@2.0.2
   no known CVEs
   surface: none
A  balanced-match@1.0.2
   no known CVEs
   surface: none
A  balanced-match@4.0.4
   no known CVEs
   surface: none
A  base-64@1.0.0
   no known CVEs
   surface: none
A  base64-js@1.5.1
   no known CVEs
   surface: none
A  base64-js@0.0.8
   no known CVEs
   surface: none
A  base64id@2.0.0
   no known CVEs
   surface: none
A  base64url@3.0.1
   no known CVEs
   surface: none
A  bcp-47-match@2.0.3
   no known CVEs
   surface: none
A  before-after-hook@2.2.3
   no known CVEs
   surface: none
A  before-after-hook@3.0.2
   no known CVEs
   surface: none
A  better-path-resolve@1.0.0
   no known CVEs
   surface: none
A  bignumber.js@9.0.2
   no known CVEs
   surface: none
A  binary-extensions@2.2.0
   no known CVEs
   surface: none
A  bindings@1.5.0
   no known CVEs
   surface: none
A  bintrees@1.0.2
   no known CVEs
   surface: none
A  blacklist@1.1.4
   no known CVEs
   surface: none
A  bn.js@4.12.3
   no known CVEs
   surface: none
A  boolbase@1.0.0
   no known CVEs
   surface: none
A  bowser@2.11.0
   no known CVEs
   surface: none
A  braces@3.0.3
   no known CVEs
   surface: none
A  bser@2.1.1
   no known CVEs
   surface: none
A  buffer@6.0.3
   no known CVEs
   surface: none
A  buffer@5.7.1
   no known CVEs
   surface: none
A  buffer-equal@0.0.1
   no known CVEs
   surface: none
A  buffer-equal-constant-time@1.0.1
   no known CVEs
   surface: none
A  buffer-from@1.1.2
   no known CVEs
   surface: none
A  bundle-name@4.1.0
   no known CVEs
   surface: none
A  bytes@3.1.2
   no known CVEs
   surface: none
A  bytes@3.1.0
   no known CVEs
   surface: none
A  call-bind@1.0.8
   no known CVEs
   surface: none
A  call-bind-apply-helpers@1.0.2
   no known CVEs
   surface: none
A  call-bound@1.0.4
   no known CVEs
   surface: none
A  callsites@3.1.0
   no known CVEs
   surface: none
A  camel-case@1.2.2
   no known CVEs
   surface: none
A  camel-case@4.1.2
   no known CVEs
   surface: none
A  camelcase@5.3.1
   no known CVEs
   surface: none
A  camelcase@8.0.0
   no known CVEs
   surface: none
A  camelcase@6.3.0
   no known CVEs
   surface: none
A  camelcase-css@2.0.1
   no known CVEs
   surface: none
A  camelcase-keys@6.2.2
   no known CVEs
   surface: none
A  camelize@1.0.0
   no known CVEs
   surface: none
A  caniuse-api@3.0.0
   no known CVEs
   surface: none
A  caniuse-lite@1.0.30001760
   no known CVEs
   surface: none
A  caniuse-lite@1.0.30001788
   no known CVEs
   surface: none
A  capital-case@1.0.4
   no known CVEs
   surface: none
A  ccount@2.0.1
   no known CVEs
   surface: none
A  chai@6.2.2
   no known CVEs
   surface: none
A  chalk@4.1.2
   no known CVEs
   surface: none
A  chalk@5.6.2
   no known CVEs
   surface: none
A  chalk@2.4.2
   no known CVEs
   surface: none
A  chalk@3.0.0
   no known CVEs
   surface: none
A  change-case@4.1.2
   no known CVEs
   surface: none
A  change-case@2.3.1
   no known CVEs
   surface: none
A  change-case-all@1.0.15
   no known CVEs
   surface: none
A  char-regex@1.0.2
   no known CVEs
   surface: none
A  character-entities@2.0.2
   no known CVEs
   surface: none
A  character-entities-html4@2.1.0
   no known CVEs
   surface: none
A  character-entities-legacy@3.0.0
   no known CVEs
   surface: none
A  character-reference-invalid@2.0.1
   no known CVEs
   surface: none
A  chardet@0.7.0
   no known CVEs
   surface: none
A  chardet@2.1.1
   no known CVEs
   surface: none
A  charenc@0.0.2
   no known CVEs
   surface: none
A  chevrotain-allstar@0.4.1
   no known CVEs
   surface: none
A  chokidar@3.6.0
   no known CVEs
   surface: none
A  chokidar@4.0.3
   no known CVEs
   surface: none
A  chownr@2.0.0
   no known CVEs
   surface: none
A  chownr@1.1.4
   no known CVEs
   surface: none
A  chownr@3.0.0
   no known CVEs
   surface: none
A  chrome-trace-event@1.0.3
   no known CVEs
   surface: none
A  ci-info@3.9.0
   no known CVEs
   surface: none
A  ci-info@2.0.0
   no known CVEs
   surface: none
A  ci-info@3.8.0
   no known CVEs
   surface: none
A  citty@0.1.6
   no known CVEs
   surface: none
A  city-timezones@1.2.1
   no known CVEs
   surface: none
A  class-transformer@0.5.1
   no known CVEs
   surface: none
A  class-variance-authority@0.7.1
   no known CVEs
   surface: none
A  classnames@2.3.2
   no known CVEs
   surface: none
A  classnames@2.5.1
   no known CVEs
   surface: none
A  clean-stack@3.0.1
   no known CVEs
   surface: none
A  clean-stack@2.2.0
   no known CVEs
   surface: none
A  cli-boxes@3.0.0
   no known CVEs
   surface: none
A  cli-boxes@2.2.1
   no known CVEs
   surface: none
A  cli-cursor@3.1.0
   no known CVEs
   surface: none
A  cli-cursor@5.0.0
   no known CVEs
   surface: none
A  cli-cursor@4.0.0
   no known CVEs
   surface: none
A  cli-progress@3.12.0
   no known CVEs
   surface: none
A  cli-spinners@2.9.2
   no known CVEs
   surface: none
A  cli-spinners@3.2.0
   no known CVEs
   surface: none
A  cli-table3@0.6.5
   no known CVEs
   surface: none
A  cli-table3@0.6.3
   no known CVEs
   surface: none
A  cli-truncate@3.1.0
   no known CVEs
   surface: none
A  cli-truncate@2.1.0
   no known CVEs
   surface: none
A  cli-truncate@4.0.0
   no known CVEs
   surface: none
A  cli-width@3.0.0
   no known CVEs
   surface: none
A  cli-width@4.1.0
   no known CVEs
   surface: none
A  client-only@0.0.1
   no known CVEs
   surface: none
A  clipboardy@4.0.0
   no known CVEs
   surface: none
A  cliui@7.0.4
   no known CVEs
   surface: none
A  cliui@8.0.1
   no known CVEs
   surface: none
A  cliui@6.0.0
   no known CVEs
   surface: none
A  clone@1.0.4
   no known CVEs
   surface: none
A  clone@2.1.2
   no known CVEs
   surface: none
A  clsx@2.1.1
   no known CVEs
   surface: none
A  cluster-key-slot@1.1.2
   no known CVEs
   surface: none
A  cmdk@0.2.0
   no known CVEs
   surface: none
A  cmk@0.1.1
   no known CVEs
   surface: none
A  co@4.6.0
   no known CVEs
   surface: none
A  code-block-writer@13.0.3
   no known CVEs
   surface: none
A  code-block-writer@12.0.0
   no known CVEs
   surface: none
A  code-excerpt@4.0.0
   no known CVEs
   surface: none
A  code-excerpt@3.0.0
   no known CVEs
   surface: none
A  collapse-white-space@2.1.0
   no known CVEs
   surface: none
A  collect-v8-coverage@1.0.2
   no known CVEs
   surface: none
A  color@3.2.1
   no known CVEs
   surface: none
A  color@4.2.3
   no known CVEs
   surface: none
A  color-convert@2.0.1
   no known CVEs
   surface: none
A  color-convert@1.9.3
   no known CVEs
   surface: none
A  color-name@1.1.4
   no known CVEs
   surface: none
A  color-name@1.1.3
   no known CVEs
   surface: none
A  color-string@1.9.1
   no known CVEs
   surface: none
A  colord@2.9.3
   no known CVEs
   surface: none
A  colorette@2.0.20
   no known CVEs
   surface: none
A  colorspace@1.1.4
   no known CVEs
   surface: none
A  combined-stream@1.0.8
   no known CVEs
   surface: none
A  comma-separated-tokens@2.0.3
   no known CVEs
   surface: none
A  command-score@0.1.2
   no known CVEs
   surface: none
A  comment-json@4.2.3
   no known CVEs
   surface: none
A  commist@1.1.0
   no known CVEs
   surface: none
A  common-tags@1.8.2
   no known CVEs
   surface: none
A  commondir@1.0.1
   no known CVEs
   surface: none
A  compare-versions@6.1.1
   no known CVEs
   surface: none
A  component-emitter@1.3.0
   no known CVEs
   surface: none
A  compute-scroll-into-view@3.1.1
   no known CVEs
   surface: none
A  compute-scroll-into-view@1.0.17
   no known CVEs
   surface: none
A  concat-map@0.0.1
   no known CVEs
   surface: none
A  concat-stream@2.0.0
   no known CVEs
   surface: none
A  confbox@0.2.2
   no known CVEs
   surface: none
A  confbox@0.1.8
   no known CVEs
   surface: none
A  consola@3.4.2
   no known CVEs
   surface: none
A  consola@2.15.3
   no known CVEs
   surface: none
A  console-control-strings@1.1.0
   no known CVEs
   surface: none
A  constant-case@3.0.4
   no known CVEs
   surface: none
A  constant-case@1.1.2
   no known CVEs
   surface: none
A  content-disposition@0.5.4
   no known CVEs
   surface: none
A  content-disposition@1.0.0
   no known CVEs
   surface: none
A  content-type@1.0.5
   no known CVEs
   surface: none
A  content-type@1.0.4
   no known CVEs
   surface: none
A  convert-source-map@2.0.0
   no known CVEs
   surface: none
A  convert-source-map@1.8.0
   no known CVEs
   surface: none
A  convert-to-spaces@2.0.1
   no known CVEs
   surface: none
A  convert-to-spaces@1.0.2
   no known CVEs
   surface: none
A  cookie@0.7.2
   no known CVEs
   surface: none
A  cookie@0.7.1
   no known CVEs
   surface: none
A  cookie-parser@1.4.6
   no known CVEs
   surface: none
A  cookie-signature@1.0.6
   no known CVEs
   surface: none
A  cookie-signature@1.2.2
   no known CVEs
   surface: none
A  cookiejar@2.1.4
   no known CVEs
   surface: none
A  copy-anything@3.0.2
   no known CVEs
   surface: none
A  copy-anything@4.0.5
   no known CVEs
   surface: none
A  copy-to-clipboard@3.3.3
   no known CVEs
   surface: none
A  core-util-is@1.0.3
   no known CVEs
   surface: none
A  cors@2.8.5
   no known CVEs
   surface: none
A  cose-base@1.0.3
   no known CVEs
   surface: none
A  cose-base@2.2.0
   no known CVEs
   surface: none
A  cosmiconfig@6.0.0
   no known CVEs
   surface: none
A  country-flag-icons@1.6.4
   no known CVEs
   surface: none
A  create-require@1.1.1
   no known CVEs
   surface: none
A  cron-parser@4.9.0
   no known CVEs
   surface: none
A  cron-parser@3.5.0
   no known CVEs
   surface: none
A  cross-inspect@1.0.1
   no known CVEs
   surface: none
A  crypt@0.0.2
   no known CVEs
   surface: none
A  crypto@1.0.1
   no known CVEs
   surface: none
A  csprng@0.1.2
   no known CVEs
   surface: none
A  css-background-parser@0.1.0
   no known CVEs
   surface: none
A  css-box-shadow@1.0.0-3
   no known CVEs
   surface: none
A  css-color-keywords@1.0.0
   no known CVEs
   surface: none
A  css-in-js-utils@3.1.0
   no known CVEs
   surface: none
A  css-select@5.1.0
   no known CVEs
   surface: none
A  css-selector-tokenizer@0.7.3
   no known CVEs
   surface: none
A  css-to-react-native@3.0.0
   no known CVEs
   surface: none
A  css-tree@3.1.0
   no known CVEs
   surface: none
A  css-tree@1.1.3
   no known CVEs
   surface: none
A  css-tree@2.2.1
   no known CVEs
   surface: none
A  css-what@6.1.0
   no known CVEs
   surface: none
A  css.escape@1.5.1
   no known CVEs
   surface: none
A  cssnano-preset-default@7.0.10
   no known CVEs
   surface: none
A  cssnano-utils@5.0.1
   no known CVEs
   surface: none
A  csso@5.0.5
   no known CVEs
   surface: none
A  cssstyle@3.0.0
   no known CVEs
   surface: none
A  cssstyle@4.6.0
   no known CVEs
   surface: none
A  csstype@3.1.3
   no known CVEs
   surface: none
A  csv-parse@5.6.0
   no known CVEs
   surface: none
A  csv-stringify@6.6.0
   no known CVEs
   surface: none
A  cytoscape-cose-bilkent@4.1.0
   no known CVEs
   surface: none
A  cytoscape-fcose@2.2.0
   no known CVEs
   surface: none
A  d3-array@3.2.4
   no known CVEs
   surface: none
A  d3-array@3.2.3
   no known CVEs
   surface: none
A  d3-array@2.12.1
   no known CVEs
   surface: none
A  d3-axis@3.0.0
   no known CVEs
   surface: none
A  d3-brush@3.0.0
   no known CVEs
   surface: none
A  d3-chord@3.0.1
   no known CVEs
   surface: none
A  d3-color@3.1.0
   no known CVEs
   surface: none
A  d3-contour@4.0.2
   no known CVEs
   surface: none
A  d3-delaunay@6.0.4
   no known CVEs
   surface: none
A  d3-dispatch@3.0.1
   no known CVEs
   surface: none
A  d3-drag@3.0.0
   no known CVEs
   surface: none
A  d3-ease@3.0.1
   no known CVEs
   surface: none
A  d3-force@3.0.0
   no known CVEs
   surface: none
A  d3-format@3.1.2
   no known CVEs
   surface: none
A  d3-format@3.1.0
   no known CVEs
   surface: none
A  d3-geo@3.1.1
   no known CVEs
   surface: none
A  d3-hierarchy@3.1.2
   no known CVEs
   surface: none
A  d3-interpolate@3.0.1
   no known CVEs
   surface: none
A  d3-path@3.1.0
   no known CVEs
   surface: none
A  d3-path@1.0.9
   no known CVEs
   surface: none
A  d3-polygon@3.0.1
   no known CVEs
   surface: none
A  d3-quadtree@3.0.1
   no known CVEs
   surface: none
A  d3-random@3.0.1
   no known CVEs
   surface: none
A  d3-sankey@0.12.3
   no known CVEs
   surface: none
A  d3-scale@4.0.2
   no known CVEs
   surface: none
A  d3-selection@3.0.0
   no known CVEs
   surface: none
A  d3-shape@3.2.0
   no known CVEs
   surface: none
A  d3-shape@1.3.7
   no known CVEs
   surface: none
A  d3-time@3.1.0
   no known CVEs
   surface: none
A  d3-time-format@4.1.0
   no known CVEs
   surface: none
A  d3-timer@3.0.1
   no known CVEs
   surface: none
A  d3-transition@3.0.1
   no known CVEs
   surface: none
A  d3-zoom@3.0.0
   no known CVEs
   surface: none
A  dagre-d3-es@7.0.14
   no known CVEs
   surface: none
A  data-uri-to-buffer@4.0.1
   no known CVEs
   surface: none
A  data-urls@4.0.0
   no known CVEs
   surface: none
A  data-urls@5.0.0
   no known CVEs
   surface: none
A  data-view-buffer@1.0.2
   no known CVEs
   surface: none
A  data-view-byte-length@1.0.2
   no known CVEs
   surface: none
A  data-view-byte-offset@1.0.1
   no known CVEs
   surface: none
A  dataloader@2.2.3
   no known CVEs
   surface: none
A  dataloader@1.4.0
   no known CVEs
   surface: none
A  date-fns@3.6.0
   no known CVEs
   surface: none
A  date-fns@4.1.0
   no known CVEs
   surface: none
A  date-fns-tz@3.2.0
   no known CVEs
   surface: none
A  dayjs@1.11.4
   no known CVEs
   surface: none
A  dayjs@1.11.20
   no known CVEs
   surface: none
A  dayjs@1.11.13
   no known CVEs
   surface: none
A  de-indent@1.0.2
   no known CVEs
   surface: none
A  debounce@1.2.1
   no known CVEs
   surface: none
A  debounce-fn@4.0.0
   no known CVEs
   surface: none
A  debug@4.4.3
   no known CVEs
   surface: none
A  debug@4.3.4
   no known CVEs
   surface: none
A  debug@4.3.7
   no known CVEs
   surface: none
A  decamelize@1.2.0
   no known CVEs
   surface: none
A  decamelize-keys@1.1.0
   no known CVEs
   surface: none
A  decimal.js-light@2.5.1
   no known CVEs
   surface: none
A  decode-named-character-reference@1.1.0
   no known CVEs
   surface: none
A  decompress-response@6.0.0
   no known CVEs
   surface: none
A  dedent@1.7.0
   no known CVEs
   surface: none
A  dedent@1.7.1
   no known CVEs
   surface: none
A  deep-extend@0.6.0
   no known CVEs
   surface: none
A  deepmerge@4.3.1
   no known CVEs
   surface: none
A  deepmerge-ts@7.1.5
   no known CVEs
   surface: none
A  defaults@1.0.3
   no known CVEs
   surface: none
A  define-data-property@1.1.4
   no known CVEs
   surface: none
A  define-lazy-prop@2.0.0
   no known CVEs
   surface: none
A  define-lazy-prop@3.0.0
   no known CVEs
   surface: none
A  define-properties@1.2.1
   no known CVEs
   surface: none
A  defu@6.1.5
   no known CVEs
   surface: none
A  delaunator@5.1.0
   no known CVEs
   surface: none
A  delayed-stream@1.0.0
   no known CVEs
   surface: none
A  delegates@1.0.0
   no known CVEs
   surface: none
A  denque@2.1.0
   no known CVEs
   surface: none
A  dependency-graph@1.0.0
   no known CVEs
   surface: none
A  dependency-graph@0.11.0
   no known CVEs
   surface: none
A  dequal@2.0.3
   no known CVEs
   surface: none
A  des.js@1.1.0
   no known CVEs
   surface: none
A  destr@2.0.5
   no known CVEs
   surface: none
A  destroy@1.2.0
   no known CVEs
   surface: none
A  detect-element-overflow@1.2.0
   no known CVEs
   surface: none
A  detect-indent@6.1.0
   no known CVEs
   surface: none
A  detect-newline@3.1.0
   no known CVEs
   surface: none
A  detect-node-es@1.1.0
   no known CVEs
   surface: none
A  devlop@1.1.0
   no known CVEs
   surface: none
A  dezalgo@1.0.4
   no known CVEs
   surface: none
A  didyoumean@1.2.2
   no known CVEs
   surface: none
A  diff-sequences@29.6.3
   no known CVEs
   surface: none
A  dijkstrajs@1.0.2
   no known CVEs
   surface: none
A  dir-glob@3.0.1
   no known CVEs
   surface: none
A  dlv@1.1.3
   no known CVEs
   surface: none
A  dom-accessibility-api@0.5.16
   no known CVEs
   surface: none
A  dom-helpers@5.2.1
   no known CVEs
   surface: none
A  dom-serializer@2.0.0
   no known CVEs
   surface: none
A  dom-walk@0.1.2
   no known CVEs
   surface: none
A  domelementtype@2.3.0
   no known CVEs
   surface: none
A  domhandler@5.0.3
   no known CVEs
   surface: none
A  dot-case@3.0.4
   no known CVEs
   surface: none
A  dot-case@1.1.2
   no known CVEs
   surface: none
A  dot-prop@6.0.1
   no known CVEs
   surface: none
A  dotenv@16.6.1
   no known CVEs
   surface: none
A  dotenv@16.4.7
   no known CVEs
   surface: none
A  dotenv@16.3.1
   no known CVEs
   surface: none
A  dotenv@16.4.1
   no known CVEs
   surface: none
A  dotenv@16.4.5
   no known CVEs
   surface: none
A  dotenv@8.6.0
   no known CVEs
   surface: none
A  dotenv-expand@10.0.0
   no known CVEs
   surface: none
A  dotenv-expand@8.0.3
   no known CVEs
   surface: none
A  downshift@6.1.9
   no known CVEs
   surface: none
A  dset@3.1.4
   no known CVEs
   surface: none
A  dunder-proto@1.0.1
   no known CVEs
   surface: none
A  duplexer@0.1.2
   no known CVEs
   surface: none
A  eastasianwidth@0.2.0
   no known CVEs
   surface: none
A  ecdsa-sig-formatter@1.0.11
   no known CVEs
   surface: none
A  ee-first@1.1.1
   no known CVEs
   surface: none
A  electron-to-chromium@1.5.336
   no known CVEs
   surface: none
A  electron-to-chromium@1.5.267
   no known CVEs
   surface: none
A  emittery@0.13.1
   no known CVEs
   surface: none
A  emoji-regex@10.5.0
   no known CVEs
   surface: none
A  emoji-regex@8.0.0
   no known CVEs
   surface: none
A  emoji-regex@9.2.2
   no known CVEs
   surface: none
A  empathic@2.0.0
   no known CVEs
   surface: none
A  enabled@2.0.0
   no known CVEs
   surface: none
A  encode-utf8@1.0.3
   no known CVEs
   surface: none
A  encodeurl@2.0.0
   no known CVEs
   surface: none
A  encodeurl@1.0.2
   no known CVEs
   surface: none
A  encoding@0.1.13
   no known CVEs
   surface: none
A  end-of-stream@1.4.4
   no known CVEs
   surface: none
A  enhanced-resolve@5.18.3
   no known CVEs
   surface: none
A  enhanced-resolve@5.20.1
   no known CVEs
   surface: none
A  enquirer@2.4.1
   no known CVEs
   surface: none
A  entities@4.5.0
   no known CVEs
   surface: none
A  entities@6.0.1
   no known CVEs
   surface: none
A  env-paths@2.2.1
   no known CVEs
   surface: none
A  environment@1.1.0
   no known CVEs
   surface: none
A  err-code@2.0.3
   no known CVEs
   surface: none
A  error-ex@1.3.2
   no known CVEs
   surface: none
A  error-stack-parser@2.1.4
   no known CVEs
   surface: none
A  error-stack-parser-es@0.1.4
   no known CVEs
   surface: none
A  es-abstract@1.24.0
   no known CVEs
   surface: none
A  es-define-property@1.0.1
   no known CVEs
   surface: none
A  es-errors@1.3.0
   no known CVEs
   surface: none
A  es-object-atoms@1.1.1
   no known CVEs
   surface: none
A  es-set-tostringtag@2.1.0
   no known CVEs
   surface: none
A  es-to-primitive@1.3.0
   no known CVEs
   surface: none
A  es6-promise@4.2.8
   no known CVEs
   surface: none
A  esast-util-from-estree@2.0.0
   no known CVEs
   surface: none
A  esast-util-from-js@2.0.1
   no known CVEs
   surface: none
A  escalade@3.2.0
   no known CVEs
   surface: none
A  escape-html@1.0.3
   no known CVEs
   surface: none
A  escape-string-regexp@4.0.0
   no known CVEs
   surface: none
A  escape-string-regexp@2.0.0
   no known CVEs
   surface: none
A  escape-string-regexp@1.0.5
   no known CVEs
   surface: none
A  escape-string-regexp@5.0.0
   no known CVEs
   surface: none
A  eslint-visitor-keys@3.4.3
   no known CVEs
   surface: none
A  esrecurse@4.3.0
   no known CVEs
   surface: none
A  estraverse@5.3.0
   no known CVEs
   surface: none
A  estraverse@4.3.0
   no known CVEs
   surface: none
A  estree-util-attach-comments@3.0.0
   no known CVEs
   surface: none
A  estree-util-build-jsx@3.0.1
   no known CVEs
   surface: none
A  estree-util-is-identifier-name@3.0.0
   no known CVEs
   surface: none
A  estree-util-scope@1.0.0
   no known CVEs
   surface: none
A  estree-util-to-js@2.0.0
   no known CVEs
   surface: none
A  estree-util-value-to-estree@3.5.0
   no known CVEs
   surface: none
A  estree-util-value-to-estree@3.4.0
   no known CVEs
   surface: none
A  estree-util-visit@2.0.0
   no known CVEs
   surface: none
A  estree-walker@3.0.3
   no known CVEs
   surface: none
A  estree-walker@2.0.2
   no known CVEs
   surface: none
A  etag@1.8.1
   no known CVEs
   surface: none
A  event-target-polyfill@0.0.4
   no known CVEs
   surface: none
A  event-target-shim@5.0.1
   no known CVEs
   surface: none
A  eventemitter3@5.0.1
   no known CVEs
   surface: none
A  eventemitter3@4.0.7
   no known CVEs
   surface: none
A  events@3.3.0
   no known CVEs
   surface: none
A  eventsource-parser@3.0.6
   no known CVEs
   surface: none
A  expand-template@2.0.3
   no known CVEs
   surface: none
A  expect@29.7.0
   no known CVEs
   surface: none
A  expect-type@1.3.0
   no known CVEs
   surface: none
A  exponential-backoff@3.1.1
   no known CVEs
   surface: none
A  extend@3.0.2
   no known CVEs
   surface: none
A  extend-shallow@2.0.1
   no known CVEs
   surface: none
A  extendable-error@0.1.7
   no known CVEs
   surface: none
A  fast-content-type-parse@2.0.1
   no known CVEs
   surface: none
A  fast-deep-equal@3.1.3
   no known CVEs
   surface: none
A  fast-equals@2.0.4
   no known CVEs
   surface: none
A  fast-glob@3.3.2
   no known CVEs
   surface: none
A  fast-levenshtein@3.0.0
   no known CVEs
   surface: none
A  fast-npm-meta@0.2.2
   no known CVEs
   surface: none
A  fast-safe-stringify@2.1.1
   no known CVEs
   surface: none
A  fast-sha256@1.3.0
   no known CVEs
   surface: none
A  fast-shallow-equal@1.0.0
   no known CVEs
   surface: none
A  fast-text-encoding@1.0.6
   no known CVEs
   surface: none
A  fastparse@1.1.2
   no known CVEs
   surface: none
A  fastq@1.13.0
   no known CVEs
   surface: none
A  fault@2.0.1
   no known CVEs
   surface: none
A  fbjs-css-vars@1.0.2
   no known CVEs
   surface: none
A  fdir@6.5.0
   no known CVEs
   surface: none
A  fecha@4.2.3
   no known CVEs
   surface: none
A  fetch-blob@3.2.0
   no known CVEs
   surface: none
A  fflate@0.8.2
   no known CVEs
   surface: none
A  fflate@0.7.4
   no known CVEs
   surface: none
A  figures@3.2.0
   no known CVEs
   surface: none
A  figures@6.1.0
   no known CVEs
   surface: none
A  figures@5.0.0
   no known CVEs
   surface: none
A  file-type@9.0.0
   no known CVEs
   surface: none
A  file-uri-to-path@1.0.0
   no known CVEs
   surface: none
A  filelist@1.0.4
   no known CVEs
   surface: none
A  fill-range@7.1.1
   no known CVEs
   surface: none
A  finalhandler@2.1.0
   no known CVEs
   surface: none
A  finalhandler@1.1.2
   no known CVEs
   surface: none
A  finalhandler@1.3.1
   no known CVEs
   surface: none
A  find-up@4.1.0
   no known CVEs
   surface: none
A  find-up@3.0.0
   no known CVEs
   surface: none
A  find-up@5.0.0
   no known CVEs
   surface: none
A  flatted@3.4.2
   no known CVEs
   surface: none
A  fnv-plus@1.3.1
   no known CVEs
   surface: none
A  for-each@0.3.5
   no known CVEs
   surface: none
A  form-data-encoder@1.7.2
   no known CVEs
   surface: none
A  formdata-node@4.4.1
   no known CVEs
   surface: none
A  formdata-polyfill@4.0.10
   no known CVEs
   surface: none
A  forwarded@0.2.0
   no known CVEs
   surface: none
A  forwarded-parse@2.1.2
   no known CVEs
   surface: none
A  fraction.js@4.3.7
   no known CVEs
   surface: none
A  framer-motion@10.12.8
   no known CVEs
   surface: none
A  fresh@0.5.2
   no known CVEs
   surface: none
A  fresh@2.0.0
   no known CVEs
   surface: none
A  fs-constants@1.0.0
   no known CVEs
   surface: none
A  fs-minipass@3.0.3
   no known CVEs
   surface: none
A  fs.realpath@1.0.0
   no known CVEs
   surface: none
A  function-bind@1.1.2
   no known CVEs
   surface: none
A  function.prototype.name@1.1.8
   no known CVEs
   surface: none
A  functions-have-names@1.2.3
   no known CVEs
   surface: none
A  gauge@4.0.4
   no known CVEs
   surface: none
A  gcp-metadata@4.3.1
   no known CVEs
   surface: none
A  gcp-metadata@6.1.0
   no known CVEs
   surface: none
A  generate-function@2.3.1
   no known CVEs
   surface: none
A  generic-pool@3.9.0
   no known CVEs
   surface: none
A  gensync@1.0.0-beta.2
   no known CVEs
   surface: none
A  get-caller-file@2.0.5
   no known CVEs
   surface: none
A  get-east-asian-width@1.3.1
   no known CVEs
   surface: none
A  get-intrinsic@1.3.0
   no known CVEs
   surface: none
A  get-nonce@1.0.1
   no known CVEs
   surface: none
A  get-package-type@0.1.0
   no known CVEs
   surface: none
A  get-proto@1.0.1
   no known CVEs
   surface: none
A  get-stream@6.0.1
   no known CVEs
   surface: none
A  get-stream@9.0.1
   no known CVEs
   surface: none
A  get-stream@8.0.1
   no known CVEs
   surface: none
A  get-symbol-description@1.1.0
   no known CVEs
   surface: none
A  get-user-locale@1.4.0
   no known CVEs
   surface: none
A  gettext-parser@8.0.0
   no known CVEs
   surface: none
A  git-repo-info@2.1.1
   no known CVEs
   surface: none
A  github-from-package@0.0.0
   no known CVEs
   surface: none
A  github-slugger@2.0.0
   no known CVEs
   surface: none
A  glob@7.2.3
   no known CVEs
   surface: none
A  glob@7.1.6
   no known CVEs
   surface: none
A  glob@8.1.0
   no known CVEs
   surface: none
A  glob@9.3.5
   no known CVEs
   surface: none
A  glob-parent@5.1.2
   no known CVEs
   surface: none
A  glob-to-regexp@0.4.1
   no known CVEs
   surface: none
A  global@4.4.0
   no known CVEs
   surface: none
A  globby@11.1.0
   no known CVEs
   surface: none
A  googleapis-common@7.0.1
   no known CVEs
   surface: none
A  googleapis-common@5.1.0
   no known CVEs
   surface: none
A  gopd@1.2.0
   no known CVEs
   surface: none
A  gradient-string@2.0.0
   no known CVEs
   surface: none
A  gradient-string@2.0.2
   no known CVEs
   surface: none
A  gradient-string@3.0.0
   no known CVEs
   surface: none
A  graphql@16.10.0
   no known CVEs
   surface: none
A  graphql@14.7.0
   no known CVEs
   surface: none
A  graphql-config@5.1.3
   no known CVEs
   surface: none
A  gtoken@5.3.2
   no known CVEs
   surface: none
A  gtoken@7.0.1
   no known CVEs
   surface: none
A  gzip-size@6.0.0
   no known CVEs
   surface: none
A  hachure-fill@0.5.2
   no known CVEs
   surface: none
A  hard-rejection@2.1.0
   no known CVEs
   surface: none
A  has-bigints@1.0.2
   no known CVEs
   surface: none
A  has-flag@4.0.0
   no known CVEs
   surface: none
A  has-flag@5.0.1
   no known CVEs
   surface: none
A  has-flag@3.0.0
   no known CVEs
   surface: none
A  has-own-prop@2.0.0
   no known CVEs
   surface: none
A  has-property-descriptors@1.0.2
   no known CVEs
   surface: none
A  has-proto@1.2.0
   no known CVEs
   surface: none
A  has-symbols@1.1.0
   no known CVEs
   surface: none
A  has-tostringtag@1.0.2
   no known CVEs
   surface: none
A  has-unicode@2.0.1
   no known CVEs
   surface: none
A  hash-base@3.1.0
   no known CVEs
   surface: none
A  hasown@2.0.2
   no known CVEs
   surface: none
A  hast-util-from-dom@5.0.1
   no known CVEs
   surface: none
A  hast-util-from-html@2.0.3
   no known CVEs
   surface: none
A  hast-util-from-html-isomorphic@2.0.0
   no known CVEs
   surface: none
A  hast-util-from-parse5@8.0.3
   no known CVEs
   surface: none
A  hast-util-is-element@3.0.0
   no known CVEs
   surface: none
A  hast-util-parse-selector@4.0.0
   no known CVEs
   surface: none
A  hast-util-raw@9.1.0
   no known CVEs
   surface: none
A  hast-util-to-estree@3.1.3
   no known CVEs
   surface: none
A  hast-util-to-html@9.0.5
   no known CVEs
   surface: none
A  hast-util-to-jsx-runtime@2.3.6
   no known CVEs
   surface: none
A  hast-util-to-parse5@8.0.1
   no known CVEs
   surface: none
A  hast-util-to-string@3.0.1
   no known CVEs
   surface: none
A  hast-util-to-text@4.0.2
   no known CVEs
   surface: none
A  hast-util-whitespace@3.0.0
   no known CVEs
   surface: none
A  hastscript@9.0.1
   no known CVEs
   surface: none
A  header-case@2.0.4
   no known CVEs
   surface: none
A  headers-polyfill@4.0.3
   no known CVEs
   surface: none
A  help-me@3.0.0
   no known CVEs
   surface: none
A  hex-rgb@4.3.0
   no known CVEs
   surface: none
A  hoist-non-react-statics@3.3.2
   no known CVEs
   surface: none
A  html-encoding-sniffer@3.0.0
   no known CVEs
   surface: none
A  html-encoding-sniffer@4.0.0
   no known CVEs
   surface: none
A  html-escaper@2.0.2
   no known CVEs
   surface: none
A  html-parse-stringify@3.0.1
   no known CVEs
   surface: none
A  html-void-elements@3.0.0
   no known CVEs
   surface: none
A  htmlparser2@8.0.2
   no known CVEs
   surface: none
A  htmlparser2@10.0.0
   no known CVEs
   surface: none
A  http_ece@1.2.0
   no known CVEs
   surface: none
A  http-cache-semantics@4.1.1
   no known CVEs
   surface: none
A  http-errors@2.0.0
   no known CVEs
   surface: none
A  http-errors@1.7.3
   no known CVEs
   surface: none
A  http-errors@2.0.1
   no known CVEs
   surface: none
A  http-parser-js@0.5.8
   no known CVEs
   surface: none
A  human-signals@2.1.0
   no known CVEs
   surface: none
A  human-signals@7.0.0
   no known CVEs
   surface: none
A  human-signals@5.0.0
   no known CVEs
   surface: none
A  humanize-duration@3.33.1
   no known CVEs
   surface: none
A  humanize-ms@1.2.1
   no known CVEs
   surface: none
A  hyperlinker@1.0.0
   no known CVEs
   surface: none
A  hyphenate-style-name@1.0.4
   no known CVEs
   surface: none
A  i18next@23.2.3
   no known CVEs
   surface: none
A  ical.js@1.5.0
   no known CVEs
   surface: none
A  iconv-lite@0.6.3
   no known CVEs
   surface: none
A  iconv-lite@0.4.24
   no known CVEs
   surface: none
A  iconv-lite@0.7.2
   no known CVEs
   surface: none
A  iconv-lite@0.7.0
   no known CVEs
   surface: none
A  ics@2.37.0
   no known CVEs
   surface: none
A  ieee754@1.2.1
   no known CVEs
   surface: none
A  ignore@5.3.2
   no known CVEs
   surface: none
A  ignore@7.0.5
   no known CVEs
   surface: none
A  image-q@4.0.0
   no known CVEs
   surface: none
A  immer@10.1.1
   no known CVEs
   surface: none
A  import-from@4.0.0
   no known CVEs
   surface: none
A  import-lazy@4.0.0
   no known CVEs
   surface: none
A  import-meta-resolve@4.2.0
   no known CVEs
   surface: none
A  imurmurhash@0.1.4
   no known CVEs
   surface: none
A  indent-string@4.0.0
   no known CVEs
   surface: none
A  indent-string@5.0.0
   no known CVEs
   surface: none
A  infer-owner@1.0.4
   no known CVEs
   surface: none
A  inflight@1.0.6
   no known CVEs
   surface: none
A  inherits@2.0.4
   no known CVEs
   surface: none
A  ini@5.0.0
   no known CVEs
   surface: none
A  ini@1.3.8
   no known CVEs
   surface: none
A  ink-progress-bar@3.0.0
   no known CVEs
   surface: none
A  ink-select-input@4.2.1
   no known CVEs
   surface: none
A  ink-spinner@5.0.0
   no known CVEs
   surface: none
A  ink-text-input@4.0.3
   no known CVEs
   surface: none
A  inline-style-parser@0.2.7
   no known CVEs
   surface: none
A  inquirer@8.2.6
   no known CVEs
   surface: none
A  inquirer@12.6.0
   no known CVEs
   surface: none
A  inquirer@8.2.1
   no known CVEs
   surface: none
A  inquirer@9.2.12
   no known CVEs
   surface: none
A  internal-slot@1.1.0
   no known CVEs
   surface: none
A  internmap@2.0.3
   no known CVEs
   surface: none
A  internmap@1.0.1
   no known CVEs
   surface: none
A  interpret@1.4.0
   no known CVEs
   surface: none
A  invariant@2.2.4
   no known CVEs
   surface: none
A  ipaddr.js@2.3.0
   no known CVEs
   surface: none
A  ipaddr.js@1.9.1
   no known CVEs
   surface: none
A  ipaddr.js@2.2.0
   no known CVEs
   surface: none
A  is-absolute@1.0.0
   no known CVEs
   surface: none
A  is-alphabetical@2.0.1
   no known CVEs
   surface: none
A  is-alphanumerical@2.0.1
   no known CVEs
   surface: none
A  is-array-buffer@3.0.5
   no known CVEs
   surface: none
A  is-arrayish@0.2.1
   no known CVEs
   surface: none
A  is-arrayish@0.3.2
   no known CVEs
   surface: none
A  is-async-function@2.0.0
   no known CVEs
   surface: none
A  is-bigint@1.1.0
   no known CVEs
   surface: none
A  is-binary-path@2.1.0
   no known CVEs
   surface: none
A  is-boolean-object@1.2.2
   no known CVEs
   surface: none
A  is-buffer@1.1.6
   no known CVEs
   surface: none
A  is-builtin-module@3.2.1
   no known CVEs
   surface: none
A  is-callable@1.2.7
   no known CVEs
   surface: none
A  is-data-view@1.0.2
   no known CVEs
   surface: none
A  is-date-object@1.1.0
   no known CVEs
   surface: none
A  is-decimal@2.0.1
   no known CVEs
   surface: none
A  is-extendable@0.1.1
   no known CVEs
   surface: none
A  is-extglob@2.1.1
   no known CVEs
   surface: none
A  is-finalizationregistry@1.1.1
   no known CVEs
   surface: none
A  is-fullwidth-code-point@3.0.0
   no known CVEs
   surface: none
A  is-fullwidth-code-point@4.0.0
   no known CVEs
   surface: none
A  is-fullwidth-code-point@5.1.0
   no known CVEs
   surface: none
A  is-function@1.0.2
   no known CVEs
   surface: none
A  is-generator-fn@2.1.0
   no known CVEs
   surface: none
A  is-generator-function@1.0.10
   no known CVEs
   surface: none
A  is-glob@4.0.3
   no known CVEs
   surface: none
A  is-hexadecimal@2.0.1
   no known CVEs
   surface: none
A  is-interactive@1.0.0
   no known CVEs
   surface: none
A  is-interactive@2.0.0
   no known CVEs
   surface: none
A  is-lambda@1.0.1
   no known CVEs
   surface: none
A  is-lower-case@2.0.2
   no known CVEs
   surface: none
A  is-lower-case@1.1.3
   no known CVEs
   surface: none
A  is-map@2.0.3
   no known CVEs
   surface: none
A  is-module@1.0.0
   no known CVEs
   surface: none
A  is-nan@1.3.2
   no known CVEs
   surface: none
A  is-negative-zero@2.0.3
   no known CVEs
   surface: none
A  is-network-error@1.3.0
   no known CVEs
   surface: none
A  is-node-process@1.2.0
   no known CVEs
   surface: none
A  is-number@7.0.0
   no known CVEs
   surface: none
A  is-number-object@1.1.1
   no known CVEs
   surface: none
A  is-obj@2.0.0
   no known CVEs
   surface: none
A  is-plain-obj@4.1.0
   no known CVEs
   surface: none
A  is-plain-obj@1.1.0
   no known CVEs
   surface: none
A  is-plain-obj@3.0.0
   no known CVEs
   surface: none
A  is-plain-object@5.0.0
   no known CVEs
   surface: none
A  is-plain-object@3.0.1
   no known CVEs
   surface: none
A  is-potential-custom-element-name@1.0.1
   no known CVEs
   surface: none
A  is-promise@4.0.0
   no known CVEs
   surface: none
A  is-property@1.0.2
   no known CVEs
   surface: none
A  is-reference@1.2.1
   no known CVEs
   surface: none
A  is-regex@1.2.1
   no known CVEs
   surface: none
A  is-relative@1.0.0
   no known CVEs
   surface: none
A  is-retry-allowed@2.2.0
   no known CVEs
   surface: none
A  is-retry-allowed@1.2.0
   no known CVEs
   surface: none
A  is-set@2.0.3
   no known CVEs
   surface: none
A  is-shared-array-buffer@1.0.4
   no known CVEs
   surface: none
A  is-stream@2.0.1
   no known CVEs
   surface: none
A  is-stream@4.0.1
   no known CVEs
   surface: none
A  is-stream@3.0.0
   no known CVEs
   surface: none
A  is-string@1.1.1
   no known CVEs
   surface: none
A  is-subdir@1.2.0
   no known CVEs
   surface: none
A  is-symbol@1.1.1
   no known CVEs
   surface: none
A  is-typed-array@1.1.15
   no known CVEs
   surface: none
A  is-unc-path@1.0.0
   no known CVEs
   surface: none
A  is-unicode-supported@0.1.0
   no known CVEs
   surface: none
A  is-unicode-supported@2.0.0
   no known CVEs
   surface: none
A  is-unicode-supported@1.3.0
   no known CVEs
   surface: none
A  is-upper-case@2.0.2
   no known CVEs
   surface: none
A  is-upper-case@1.1.2
   no known CVEs
   surface: none
A  is-url@1.2.4
   no known CVEs
   surface: none
A  is-weakmap@2.0.2
   no known CVEs
   surface: none
A  is-weakref@1.1.1
   no known CVEs
   surface: none
A  is-weakset@2.0.3
   no known CVEs
   surface: none
A  is-what@4.1.7
   no known CVEs
   surface: none
A  is-what@5.5.0
   no known CVEs
   surface: none
A  is-windows@1.0.2
   no known CVEs
   surface: none
A  is-wsl@2.2.0
   no known CVEs
   surface: none
A  is-wsl@3.1.0
   no known CVEs
   surface: none
A  is64bit@2.0.0
   no known CVEs
   surface: none
A  isarray@2.0.5
   no known CVEs
   surface: none
A  isbot@5.1.30
   no known CVEs
   surface: none
A  isexe@3.1.1
   no known CVEs
   surface: none
A  istanbul-lib-coverage@3.2.0
   no known CVEs
   surface: none
A  istanbul-lib-coverage@3.2.2
   no known CVEs
   surface: none
A  istanbul-lib-source-maps@5.0.6
   no known CVEs
   surface: none
A  istanbul-lib-source-maps@4.0.1
   no known CVEs
   surface: none
A  iterall@1.3.0
   no known CVEs
   surface: none
A  iterare@1.2.1
   no known CVEs
   surface: none
A  jackspeak@2.3.6
   no known CVEs
   surface: none
A  jackspeak@4.1.1
   no known CVEs
   surface: none
A  jackspeak@3.4.3
   no known CVEs
   surface: none
A  jest-changed-files@29.7.0
   no known CVEs
   surface: none
A  jest-circus@29.7.0
   no known CVEs
   surface: none
A  jest-date-mock@1.0.10
   no known CVEs
   surface: none
A  jest-diff@29.7.0
   no known CVEs
   surface: none
A  jest-docblock@29.7.0
   no known CVEs
   surface: none
A  jest-each@29.7.0
   no known CVEs
   surface: none
A  jest-environment-node@29.7.0
   no known CVEs
   surface: none
A  jest-get-type@29.6.3
   no known CVEs
   surface: none
A  jest-leak-detector@29.7.0
   no known CVEs
   surface: none
A  jest-matcher-utils@29.7.0
   no known CVEs
   surface: none
A  jest-message-util@29.7.0
   no known CVEs
   surface: none
A  jest-mock@29.7.0
   no known CVEs
   surface: none
A  jest-regex-util@29.6.3
   no known CVEs
   surface: none
A  jest-resolve-dependencies@29.7.0
   no known CVEs
   surface: none
A  jest-summarizing-reporter@1.1.4
   no known CVEs
   surface: none
A  jest-validate@29.7.0
   no known CVEs
   surface: none
A  jest-watcher@29.7.0
   no known CVEs
   surface: none
A  jju@1.4.0
   no known CVEs
   surface: none
A  jose@6.1.3
   no known CVEs
   surface: none
A  jose@6.0.11
   no known CVEs
   surface: none
A  jotai@2.12.2
   no known CVEs
   surface: none
A  jpeg-js@0.4.4
   no known CVEs
   surface: none
A  js-base64@3.7.7
   no known CVEs
   surface: none
A  js-md4@0.3.2
   no known CVEs
   surface: none
A  js-sdsl@4.3.0
   no known CVEs
   surface: none
A  js-tokens@4.0.0
   no known CVEs
   surface: none
A  js-tokens@10.0.0
   no known CVEs
   surface: none
A  jsbn@1.1.0
   no known CVEs
   surface: none
A  json-bigint@1.0.0
   no known CVEs
   surface: none
A  json-parse-better-errors@1.0.2
   no known CVEs
   surface: none
A  json-parse-even-better-errors@2.3.1
   no known CVEs
   surface: none
A  json-schema@0.4.0
   no known CVEs
   surface: none
A  json-schema-traverse@1.0.0
   no known CVEs
   surface: none
A  json-schema-traverse@0.4.1
   no known CVEs
   surface: none
A  json-schema-typed@7.0.3
   no known CVEs
   surface: none
A  json-schema-typed@8.0.2
   no known CVEs
   surface: none
A  json-stable-stringify@1.3.0
   no known CVEs
   surface: none
A  json-to-pretty-yaml@1.2.2
   no known CVEs
   surface: none
A  jsonc-parser@3.2.0
   no known CVEs
   surface: none
A  jsonc-parser@3.2.1
   no known CVEs
   surface: none
A  jsonc-parser@3.3.1
   no known CVEs
   surface: none
A  jsonify@0.0.1
   no known CVEs
   surface: none
A  jsonwebtoken@9.0.0
   no known CVEs
   surface: none
A  jwa@2.0.1
   no known CVEs
   surface: none
A  jws@4.0.1
   no known CVEs
   surface: none
A  jwt-decode@3.1.2
   no known CVEs
   surface: none
A  kbar@0.1.0-beta.36
   no known CVEs
   surface: none
A  khroma@2.1.0
   no known CVEs
   surface: none
A  kind-of@6.0.3
   no known CVEs
   surface: none
A  kleur@3.0.3
   no known CVEs
   surface: none
A  kolorist@1.8.0
   no known CVEs
   surface: none
A  kuler@2.0.0
   no known CVEs
   surface: none
A  langium@4.2.2
   no known CVEs
   surface: none
A  layout-base@1.0.2
   no known CVEs
   surface: none
A  layout-base@2.0.1
   no known CVEs
   surface: none
A  leven@2.1.0
   no known CVEs
   surface: none
A  leven@3.1.0
   no known CVEs
   surface: none
A  lexical@0.9.0
   no known CVEs
   surface: none
A  lilconfig@2.1.0
   no known CVEs
   surface: none
A  lilconfig@2.0.5
   no known CVEs
   surface: none
A  limiter@1.1.5
   no known CVEs
   surface: none
A  lines-and-columns@1.2.4
   no known CVEs
   surface: none
A  listr2@4.0.5
   no known CVEs
   surface: none
A  load-bmfont@1.4.1
   no known CVEs
   surface: none
A  load-json-file@5.3.0
   no known CVEs
   surface: none
A  load-json-file@4.0.0
   no known CVEs
   surface: none
A  locate-path@5.0.0
   no known CVEs
   surface: none
A  locate-path@3.0.0
   no known CVEs
   surface: none
A  locate-path@6.0.0
   no known CVEs
   surface: none
A  lodash.camelcase@4.3.0
   no known CVEs
   surface: none
A  lodash.castarray@4.4.0
   no known CVEs
   surface: none
A  lodash.clonedeep@4.5.0
   no known CVEs
   surface: none
A  lodash.debounce@4.0.8
   no known CVEs
   surface: none
A  lodash.defaults@4.2.0
   no known CVEs
   surface: none
A  lodash.get@4.4.2
   no known CVEs
   surface: none
A  lodash.isarguments@3.1.0
   no known CVEs
   surface: none
A  lodash.isequal@4.5.0
   no known CVEs
   surface: none
A  lodash.isplainobject@4.0.6
   no known CVEs
   surface: none
A  lodash.memoize@4.1.2
   no known CVEs
   surface: none
A  lodash.once@4.1.1
   no known CVEs
   surface: none
A  lodash.reduce@4.6.0
   no known CVEs
   surface: none
A  lodash.sortby@4.7.0
   no known CVEs
   surface: none
A  lodash.startcase@4.4.0
   no known CVEs
   surface: none
A  lodash.startswith@4.2.1
   no known CVEs
   surface: none
A  lodash.throttle@4.1.1
   no known CVEs
   surface: none
A  lodash.uniq@4.5.0
   no known CVEs
   surface: none
A  log-symbols@4.1.0
   no known CVEs
   surface: none
A  log-symbols@6.0.0
   no known CVEs
   surface: none
A  log-update@4.0.0
   no known CVEs
   surface: none
A  log-update@6.1.0
   no known CVEs
   surface: none
A  logform@2.7.0
   no known CVEs
   surface: none
A  loglevel@1.9.2
   no known CVEs
   surface: none
A  long@5.2.3
   no known CVEs
   surface: none
A  long-timeout@0.1.1
   no known CVEs
   surface: none
A  longest-streak@3.1.0
   no known CVEs
   surface: none
A  lower-case@1.1.4
   no known CVEs
   surface: none
A  lower-case@2.0.2
   no known CVEs
   surface: none
A  lower-case-first@2.0.2
   no known CVEs
   surface: none
A  lower-case-first@1.0.2
   no known CVEs
   surface: none
A  lru-cache@6.0.0
   no known CVEs
   surface: none
A  lru-cache@4.0.2
   no known CVEs
   surface: none
A  lru-cache@5.1.1
   no known CVEs
   surface: none
A  lru-memoizer@2.1.4
   no known CVEs
   surface: none
A  lru.min@1.1.2
   no known CVEs
   surface: none
A  lucide-react@0.555.0
   no known CVEs
   surface: none
A  lucide-static@0.424.0
   no known CVEs
   surface: none
A  luxon@3.4.4
   no known CVEs
   surface: none
A  luxon@1.28.1
   no known CVEs
   surface: none
A  luxon@3.3.0
   no known CVEs
   surface: none
A  magic-string@0.30.21
   no known CVEs
   surface: none
A  magic-string@0.30.19
   no known CVEs
   surface: none
A  magic-string@0.30.8
   no known CVEs
   surface: none
A  magic-string@0.30.5
   no known CVEs
   surface: none
A  make-dir@4.0.0
   no known CVEs
   surface: none
A  make-dir@3.1.0
   no known CVEs
   surface: none
A  make-error@1.3.6
   no known CVEs
   surface: none
A  make-event-props@1.3.0
   no known CVEs
   surface: none
A  makeerror@1.0.12
   no known CVEs
   surface: none
A  map-cache@0.2.2
   no known CVEs
   surface: none
A  map-obj@4.3.0
   no known CVEs
   surface: none
A  map-obj@1.0.1
   no known CVEs
   surface: none
A  markdown-extensions@2.0.0
   no known CVEs
   surface: none
A  markdown-table@3.0.4
   no known CVEs
   surface: none
A  matchit@1.1.0
   no known CVEs
   surface: none
A  math-intrinsics@1.1.0
   no known CVEs
   surface: none
A  md5@2.3.0
   no known CVEs
   surface: none
A  mdast-util-find-and-replace@3.0.2
   no known CVEs
   surface: none
A  mdast-util-from-markdown@2.0.2
   no known CVEs
   surface: none
A  mdast-util-frontmatter@2.0.1
   no known CVEs
   surface: none
A  mdast-util-gfm@3.1.0
   no known CVEs
   surface: none
A  mdast-util-gfm-autolink-literal@2.0.1
   no known CVEs
   surface: none
A  mdast-util-gfm-footnote@2.1.0
   no known CVEs
   surface: none
A  mdast-util-gfm-strikethrough@2.0.0
   no known CVEs
   surface: none
A  mdast-util-gfm-table@2.0.0
   no known CVEs
   surface: none
A  mdast-util-gfm-task-list-item@2.0.0
   no known CVEs
   surface: none
A  mdast-util-math@3.0.0
   no known CVEs
   surface: none
A  mdast-util-mdx@3.0.0
   no known CVEs
   surface: none
A  mdast-util-mdx-expression@2.0.1
   no known CVEs
   surface: none
A  mdast-util-mdx-jsx@3.2.0
   no known CVEs
   surface: none
A  mdast-util-mdxjs-esm@2.0.1
   no known CVEs
   surface: none
A  mdast-util-phrasing@4.1.0
   no known CVEs
   surface: none
A  mdast-util-to-hast@13.2.1
   no known CVEs
   surface: none
A  mdast-util-to-markdown@2.1.2
   no known CVEs
   surface: none
A  mdast-util-to-string@4.0.0
   no known CVEs
   surface: none
A  mdn-data@2.12.2
   no known CVEs
   surface: none
A  mdn-data@2.0.14
   no known CVEs
   surface: none
A  mdn-data@2.0.28
   no known CVEs
   surface: none
A  mdurl@2.0.0
   no known CVEs
   surface: none
A  media-typer@0.3.0
   no known CVEs
   surface: none
A  media-typer@1.1.0
   no known CVEs
   surface: none
A  memoize-one@6.0.0
   no known CVEs
   surface: none
A  memory-cache@0.2.0
   no known CVEs
   surface: none
A  memory-pager@1.5.0
   no known CVEs
   surface: none
A  meow@9.0.0
   no known CVEs
   surface: none
A  merge-class-names@1.4.2
   no known CVEs
   surface: none
A  merge-descriptors@2.0.0
   no known CVEs
   surface: none
A  merge-descriptors@1.0.1
   no known CVEs
   surface: none
A  merge-descriptors@1.0.3
   no known CVEs
   surface: none
A  merge-refs@1.0.0
   no known CVEs
   surface: none
A  merge-stream@2.0.0
   no known CVEs
   surface: none
A  merge2@1.4.1
   no known CVEs
   surface: none
A  meros@1.3.0
   no known CVEs
   surface: none
A  mhchemparser@4.2.1
   no known CVEs
   surface: none
A  micromark@4.0.2
   no known CVEs
   surface: none
A  micromark-core-commonmark@2.0.3
   no known CVEs
   surface: none
A  micromark-extension-frontmatter@2.0.0
   no known CVEs
   surface: none
A  micromark-extension-gfm@3.0.0
   no known CVEs
   surface: none
A  micromark-extension-gfm-footnote@2.1.0
   no known CVEs
   surface: none
A  micromark-extension-gfm-strikethrough@2.1.0
   no known CVEs
   surface: none
A  micromark-extension-gfm-table@2.1.1
   no known CVEs
   surface: none
A  micromark-extension-gfm-tagfilter@2.0.0
   no known CVEs
   surface: none
A  micromark-extension-gfm-task-list-item@2.1.0
   no known CVEs
   surface: none
A  micromark-extension-math@3.1.0
   no known CVEs
   surface: none
A  micromark-extension-mdx-expression@3.0.1
   no known CVEs
   surface: none
A  micromark-extension-mdx-jsx@3.0.2
   no known CVEs
   surface: none
A  micromark-extension-mdx-md@2.0.0
   no known CVEs
   surface: none
A  micromark-extension-mdxjs@3.0.0
   no known CVEs
   surface: none
A  micromark-extension-mdxjs-esm@3.0.0
   no known CVEs
   surface: none
A  micromark-factory-destination@2.0.1
   no known CVEs
   surface: none
A  micromark-factory-label@2.0.1
   no known CVEs
   surface: none
A  micromark-factory-mdx-expression@2.0.3
   no known CVEs
   surface: none
A  micromark-factory-space@2.0.1
   no known CVEs
   surface: none
A  micromark-factory-title@2.0.1
   no known CVEs
   surface: none
A  micromark-factory-whitespace@2.0.1
   no known CVEs
   surface: none
A  micromark-util-character@2.1.1
   no known CVEs
   surface: none
A  micromark-util-chunked@2.0.1
   no known CVEs
   surface: none
A  micromark-util-classify-character@2.0.1
   no known CVEs
   surface: none
A  micromark-util-combine-extensions@2.0.1
   no known CVEs
   surface: none
A  micromark-util-decode-numeric-character-reference@2.0.2
   no known CVEs
   surface: none
A  micromark-util-decode-string@2.0.1
   no known CVEs
   surface: none
A  micromark-util-encode@2.0.1
   no known CVEs
   surface: none
A  micromark-util-events-to-acorn@2.0.3
   no known CVEs
   surface: none
A  micromark-util-html-tag-name@2.0.1
   no known CVEs
   surface: none
A  micromark-util-normalize-identifier@2.0.1
   no known CVEs
   surface: none
A  micromark-util-resolve-all@2.0.1
   no known CVEs
   surface: none
A  micromark-util-sanitize-uri@2.0.1
   no known CVEs
   surface: none
A  micromark-util-subtokenize@2.1.0
   no known CVEs
   surface: none
A  micromark-util-symbol@2.0.1
   no known CVEs
   surface: none
A  micromark-util-types@2.0.2
   no known CVEs
   surface: none
A  micromatch@4.0.8
   no known CVEs
   surface: none
A  mime-db@1.52.0
   no known CVEs
   surface: none
A  mime-db@1.54.0
   no known CVEs
   surface: none
A  mime-types@2.1.35
   no known CVEs
   surface: none
A  mime-types@3.0.1
   no known CVEs
   surface: none
A  mimic-fn@3.1.0
   no known CVEs
   surface: none
A  mimic-fn@2.1.0
   no known CVEs
   surface: none
A  mimic-fn@4.0.0
   no known CVEs
   surface: none
A  mimic-function@5.0.1
   no known CVEs
   surface: none
A  mimic-response@3.1.0
   no known CVEs
   surface: none
A  min-document@2.19.1
   no known CVEs
   surface: none
A  min-indent@1.0.1
   no known CVEs
   surface: none
A  minimal-polyfills@2.2.3
   no known CVEs
   surface: none
A  minimalistic-assert@1.0.1
   no known CVEs
   surface: none
A  minimatch@9.0.9
   no known CVEs
   surface: none
A  minimatch@10.2.5
   no known CVEs
   surface: none
A  minimatch@3.1.5
   no known CVEs
   surface: none
A  minimatch@5.1.9
   no known CVEs
   surface: none
A  minimatch@8.0.7
   no known CVEs
   surface: none
A  minimatch@10.2.4
   no known CVEs
   surface: none
A  minimist@1.2.8
   no known CVEs
   surface: none
A  minimist-options@4.1.0
   no known CVEs
   surface: none
A  minipass@7.1.2
   no known CVEs
   surface: none
A  minipass@3.3.6
   no known CVEs
   surface: none
A  minipass@6.0.2
   no known CVEs
   surface: none
A  minipass@4.2.8
   no known CVEs
   surface: none
A  minipass-collect@1.0.2
   no known CVEs
   surface: none
A  minipass-collect@2.0.1
   no known CVEs
   surface: none
A  minipass-flush@1.0.5
   no known CVEs
   surface: none
A  minipass-pipeline@1.2.4
   no known CVEs
   surface: none
A  minipass-sized@1.0.3
   no known CVEs
   surface: none
A  minizlib@2.1.2
   no known CVEs
   surface: none
A  minizlib@3.1.0
   no known CVEs
   surface: none
A  mj-context-menu@0.6.1
   no known CVEs
   surface: none
A  mkdirp-classic@0.5.3
   no known CVEs
   surface: none
A  mnemonist@0.38.3
   no known CVEs
   surface: none
A  module-details-from-path@1.0.3
   no known CVEs
   surface: none
A  module-details-from-path@1.0.4
   no known CVEs
   surface: none
A  moment@2.29.4
   no known CVEs
   surface: none
A  mongodb-connection-string-url@3.0.0
   no known CVEs
   surface: none
A  mri@1.2.0
   no known CVEs
   surface: none
A  mrmime@2.0.0
   no known CVEs
   surface: none
A  ms@2.1.3
   no known CVEs
   surface: none
A  ms@2.1.2
   no known CVEs
   surface: none
A  ms@2.0.0
   no known CVEs
   surface: none
A  muggle-string@0.4.1
   no known CVEs
   surface: none
A  multistream@3.1.0
   no known CVEs
   surface: none
A  mute-stream@0.0.8
   no known CVEs
   surface: none
A  mute-stream@2.0.0
   no known CVEs
   surface: none
A  mute-stream@1.0.0
   no known CVEs
   surface: none
A  named-placeholders@1.1.3
   no known CVEs
   surface: none
A  nano-css@5.6.2
   no known CVEs
   surface: none
A  nanoclone@0.2.1
   no known CVEs
   surface: none
A  native-duplexpair@1.0.0
   no known CVEs
   surface: none
A  natural-compare@1.4.0
   no known CVEs
   surface: none
A  natural-orderby@2.0.3
   no known CVEs
   surface: none
A  negotiator@0.6.4
   no known CVEs
   surface: none
A  negotiator@1.0.0
   no known CVEs
   surface: none
A  negotiator@0.6.3
   no known CVEs
   surface: none
A  neo-async@2.6.2
   no known CVEs
   surface: none
A  nest-winston@1.9.4
   no known CVEs
   surface: none
A  next-router-mock@0.9.12
   no known CVEs
   surface: none
A  next-seo@6.1.0
   no known CVEs
   surface: none
A  next-themes@0.2.0
   no known CVEs
   surface: none
A  nice-try@1.0.5
   no known CVEs
   surface: none
A  nlcst-to-string@4.0.0
   no known CVEs
   surface: none
A  no-case@3.0.4
   no known CVEs
   surface: none
A  node-abi@3.75.0
   no known CVEs
   surface: none
A  node-domexception@1.0.0
   no known CVEs
   surface: none
A  node-html-parser@6.1.13
   no known CVEs
   surface: none
A  node-ical@0.16.1
   no known CVEs
   surface: none
A  node-int64@0.4.0
   no known CVEs
   surface: none
A  node-releases@2.0.37
   no known CVEs
   surface: none
A  node-releases@2.0.27
   no known CVEs
   surface: none
A  node-schedule@2.1.0
   no known CVEs
   surface: none
A  normalize-package-data@2.5.0
   no known CVEs
   surface: none
A  normalize-package-data@3.0.3
   no known CVEs
   surface: none
A  normalize-path@3.0.0
   no known CVEs
   surface: none
A  normalize-path@2.1.1
   no known CVEs
   surface: none
A  normalize-range@0.1.2
   no known CVEs
   surface: none
A  normalize-wheel@1.0.1
   no known CVEs
   surface: none
A  npm-run-path@4.0.1
   no known CVEs
   surface: none
A  npm-run-path@5.3.0
   no known CVEs
   surface: none
A  npm-to-yarn@3.0.1
   no known CVEs
   surface: none
A  nth-check@2.1.1
   no known CVEs
   surface: none
A  nullthrows@1.1.1
   no known CVEs
   surface: none
A  number-allocator@1.0.14
   no known CVEs
   surface: none
A  nuqs@2.8.2
   no known CVEs
   surface: none
A  nwsapi@2.2.21
   no known CVEs
   surface: none
A  oauth4webapi@3.7.0
   no known CVEs
   surface: none
A  object-assign@4.1.1
   no known CVEs
   surface: none
A  object-hash@3.0.0
   no known CVEs
   surface: none
A  object-hash@2.2.0
   no known CVEs
   surface: none
A  object-inspect@1.13.4
   no known CVEs
   surface: none
A  object-keys@1.1.1
   no known CVEs
   surface: none
A  object-treeify@1.1.33
   no known CVEs
   surface: none
A  object.assign@4.1.7
   no known CVEs
   surface: none
A  obliterator@1.6.1
   no known CVEs
   surface: none
A  obuf@1.1.2
   no known CVEs
   surface: none
A  obug@2.1.1
   no known CVEs
   surface: none
A  octokit@4.0.2
   no known CVEs
   surface: none
A  ohash@2.0.11
   no known CVEs
   surface: none
A  ohash@1.1.6
   no known CVEs
   surface: none
A  oidc-token-hash@5.0.1
   no known CVEs
   surface: none
A  ollama-ai-provider@1.2.0
   no known CVEs
   surface: none
A  on-finished@2.4.1
   no known CVEs
   surface: none
A  on-finished@2.3.0
   no known CVEs
   surface: none
A  once@1.4.0
   no known CVEs
   surface: none
A  one-time@1.0.0
   no known CVEs
   surface: none
A  onetime@5.1.2
   no known CVEs
   surface: none
A  onetime@7.0.0
   no known CVEs
   surface: none
A  onetime@6.0.0
   no known CVEs
   surface: none
A  oniguruma-parser@0.12.1
   no known CVEs
   surface: none
A  oniguruma-to-es@4.3.5
   no known CVEs
   surface: none
A  openid-client@6.5.0
   no known CVEs
   surface: none
A  options-defaults@2.0.40
   no known CVEs
   surface: none
A  ora@5.4.1
   no known CVEs
   surface: none
A  ora@8.1.1
   no known CVEs
   surface: none
A  os-paths@7.4.0
   no known CVEs
   surface: none
A  os-tmpdir@1.0.2
   no known CVEs
   surface: none
A  otplib@12.0.1
   no known CVEs
   surface: none
A  outdent@0.5.0
   no known CVEs
   surface: none
A  outvariant@1.4.3
   no known CVEs
   surface: none
A  own-keys@1.0.1
   no known CVEs
   surface: none
A  p-filter@2.1.0
   no known CVEs
   surface: none
A  p-finally@1.0.0
   no known CVEs
   surface: none
A  p-limit@6.2.0
   no known CVEs
   surface: none
A  p-limit@2.3.0
   no known CVEs
   surface: none
A  p-limit@3.1.0
   no known CVEs
   surface: none
A  p-locate@4.1.0
   no known CVEs
   surface: none
A  p-locate@3.0.0
   no known CVEs
   surface: none
A  p-locate@5.0.0
   no known CVEs
   surface: none
A  p-map@4.0.0
   no known CVEs
   surface: none
A  p-map@2.1.0
   no known CVEs
   surface: none
A  p-queue@6.6.2
   no known CVEs
   surface: none
A  p-retry@6.2.1
   no known CVEs
   surface: none
A  p-timeout@3.2.0
   no known CVEs
   surface: none
A  p-try@2.2.0
   no known CVEs
   surface: none
A  package-json-from-dist@1.0.1
   no known CVEs
   surface: none
A  package-manager-detector@0.2.11
   no known CVEs
   surface: none
A  package-manager-detector@1.6.0
   no known CVEs
   surface: none
A  pako@0.2.9
   no known CVEs
   surface: none
A  pako@1.0.11
   no known CVEs
   surface: none
A  param-case@3.0.4
   no known CVEs
   surface: none
A  param-case@1.1.2
   no known CVEs
   surface: none
A  parent-module@1.0.1
   no known CVEs
   surface: none
A  parse-bmfont-ascii@1.0.6
   no known CVEs
   surface: none
A  parse-bmfont-binary@1.0.6
   no known CVEs
   surface: none
A  parse-bmfont-xml@1.1.4
   no known CVEs
   surface: none
A  parse-css-color@0.2.1
   no known CVEs
   surface: none
A  parse-entities@4.0.2
   no known CVEs
   surface: none
A  parse-filepath@1.0.2
   no known CVEs
   surface: none
A  parse-headers@2.0.5
   no known CVEs
   surface: none
A  parse-json@5.2.0
   no known CVEs
   surface: none
A  parse-json@4.0.0
   no known CVEs
   surface: none
A  parse-latin@7.0.0
   no known CVEs
   surface: none
A  parse-ms@4.0.0
   no known CVEs
   surface: none
A  parse-my-command@0.3.31
   no known CVEs
   surface: none
A  parse-numeric-range@1.3.0
   no known CVEs
   surface: none
A  parse-srcset@1.0.2
   no known CVEs
   surface: none
A  parse5@7.2.1
   no known CVEs
   surface: none
A  parseurl@1.3.3
   no known CVEs
   surface: none
A  partial-json@0.1.7
   no known CVEs
   surface: none
A  pascal-case@3.1.2
   no known CVEs
   surface: none
A  pascal-case@1.1.2
   no known CVEs
   surface: none
A  passport-jwt@4.0.1
   no known CVEs
   surface: none
A  passport-strategy@1.0.0
   no known CVEs
   surface: none
A  password-prompt@1.1.3
   no known CVEs
   surface: none
A  patch-console@2.0.0
   no known CVEs
   surface: none
A  patch-console@1.0.0
   no known CVEs
   surface: none
A  path-browserify@1.0.1
   no known CVEs
   surface: none
A  path-case@3.0.4
   no known CVEs
   surface: none
A  path-case@1.1.2
   no known CVEs
   surface: none
A  path-data-parser@0.1.0
   no known CVEs
   surface: none
A  path-exists@4.0.0
   no known CVEs
   surface: none
A  path-exists@3.0.0
   no known CVEs
   surface: none
A  path-expression-matcher@1.5.0
   no known CVEs
   surface: none
A  path-is-absolute@1.0.1
   no known CVEs
   surface: none
A  path-key@3.1.1
   no known CVEs
   surface: none
A  path-key@2.0.1
   no known CVEs
   surface: none
A  path-key@4.0.0
   no known CVEs
   surface: none
A  path-parse@1.0.7
   no known CVEs
   surface: none
A  path-root@0.1.1
   no known CVEs
   surface: none
A  path-root-regex@0.1.2
   no known CVEs
   surface: none
A  path-scurry@1.11.1
   no known CVEs
   surface: none
A  path-scurry@2.0.1
   no known CVEs
   surface: none
A  path-to-regexp@3.3.0
   no known CVEs
   surface: none
A  path-to-regexp@8.4.0
   no known CVEs
   surface: none
A  path-to-regexp@6.3.0
   no known CVEs
   surface: none
A  path-to-regexp@0.1.13
   no known CVEs
   surface: none
A  path-type@4.0.0
   no known CVEs
   surface: none
A  path-type@3.0.0
   no known CVEs
   surface: none
A  pathe@2.0.3
   no known CVEs
   surface: none
A  pathe@1.1.2
   no known CVEs
   surface: none
A  pause@0.0.1
   no known CVEs
   surface: none
A  perfect-debounce@1.0.0
   no known CVEs
   surface: none
A  pg-cloudflare@1.2.5
   no known CVEs
   surface: none
A  pg-connection-string@2.9.1
   no known CVEs
   surface: none
A  pg-int8@1.0.1
   no known CVEs
   surface: none
A  pg-numeric@1.0.2
   no known CVEs
   surface: none
A  pg-pool@3.10.1
   no known CVEs
   surface: none
A  pg-protocol@1.10.3
   no known CVEs
   surface: none
A  pg-types@2.2.0
   no known CVEs
   surface: none
A  pg-types@4.0.2
   no known CVEs
   surface: none
A  pgpass@1.0.5
   no known CVEs
   surface: none
A  php-array-reader@2.1.2
   no known CVEs
   surface: none
A  php-parser@3.2.5
   no known CVEs
   surface: none
A  picocolors@1.1.1
   no known CVEs
   surface: none
A  picomatch@4.0.4
   no known CVEs
   surface: none
A  picomatch@2.3.2
   no known CVEs
   surface: none
A  picomatch@3.0.2
   no known CVEs
   surface: none
A  picomatch-browser@2.2.6
   no known CVEs
   surface: none
A  pify@4.0.1
   no known CVEs
   surface: none
A  pify@3.0.0
   no known CVEs
   surface: none
A  pify@2.3.0
   no known CVEs
   surface: none
A  pirates@4.0.6
   no known CVEs
   surface: none
A  pkce-challenge@5.0.0
   no known CVEs
   surface: none
A  pkg-dir@4.2.0
   no known CVEs
   surface: none
A  pkg-up@3.1.0
   no known CVEs
   surface: none
A  plist@3.1.0
   no known CVEs
   surface: none
A  pluralize@8.0.0
   no known CVEs
   surface: none
A  pngjs@3.4.0
   no known CVEs
   surface: none
A  pngjs@5.0.0
   no known CVEs
   surface: none
A  points-on-curve@0.2.0
   no known CVEs
   surface: none
A  points-on-path@0.2.1
   no known CVEs
   surface: none
A  possible-typed-array-names@1.0.0
   no known CVEs
   surface: none
A  postcss-calc@10.1.1
   no known CVEs
   surface: none
A  postcss-colormin@7.0.5
   no known CVEs
   surface: none
A  postcss-convert-values@7.0.8
   no known CVEs
   surface: none
A  postcss-discard-comments@7.0.5
   no known CVEs
   surface: none
A  postcss-discard-duplicates@7.0.2
   no known CVEs
   surface: none
A  postcss-discard-empty@7.0.1
   no known CVEs
   surface: none
A  postcss-discard-overridden@7.0.1
   no known CVEs
   surface: none
A  postcss-import@16.1.0
   no known CVEs
   surface: none
A  postcss-js@4.0.1
   no known CVEs
   surface: none
A  postcss-merge-longhand@7.0.5
   no known CVEs
   surface: none
A  postcss-merge-rules@7.0.7
   no known CVEs
   surface: none
A  postcss-minify-font-values@7.0.1
   no known CVEs
   surface: none
A  postcss-minify-gradients@7.0.1
   no known CVEs
   surface: none
A  postcss-minify-params@7.0.5
   no known CVEs
   surface: none
A  postcss-minify-selectors@7.0.5
   no known CVEs
   surface: none
A  postcss-nested@6.0.1
   no known CVEs
   surface: none
A  postcss-normalize-charset@7.0.1
   no known CVEs
   surface: none
A  postcss-normalize-display-values@7.0.1
   no known CVEs
   surface: none
A  postcss-normalize-positions@7.0.1
   no known CVEs
   surface: none
A  postcss-normalize-repeat-style@7.0.1
   no known CVEs
   surface: none
A  postcss-normalize-string@7.0.1
   no known CVEs
   surface: none
A  postcss-normalize-timing-functions@7.0.1
   no known CVEs
   surface: none
A  postcss-normalize-unicode@7.0.5
   no known CVEs
   surface: none
A  postcss-normalize-url@7.0.1
   no known CVEs
   surface: none
A  postcss-normalize-whitespace@7.0.1
   no known CVEs
   surface: none
A  postcss-ordered-values@7.0.2
   no known CVEs
   surface: none
A  postcss-prefixer@3.0.0
   no known CVEs
   surface: none
A  postcss-prefixwrap@1.57.0
   no known CVEs
   surface: none
A  postcss-reduce-initial@7.0.5
   no known CVEs
   surface: none
A  postcss-reduce-transforms@7.0.1
   no known CVEs
   surface: none
A  postcss-reporter@7.1.0
   no known CVEs
   surface: none
A  postcss-selector-parser@7.1.1
   no known CVEs
   surface: none
A  postcss-selector-parser@6.0.11
   no known CVEs
   surface: none
A  postcss-svgo@7.1.0
   no known CVEs
   surface: none
A  postcss-unique-selectors@7.0.4
   no known CVEs
   surface: none
A  postcss-value-parser@4.2.0
   no known CVEs
   surface: none
A  postgres-array@3.0.4
   no known CVEs
   surface: none
A  postgres-array@2.0.0
   no known CVEs
   surface: none
A  postgres-bytea@1.0.0
   no known CVEs
   surface: none
A  postgres-bytea@3.0.0
   no known CVEs
   surface: none
A  postgres-date@1.0.7
   no known CVEs
   surface: none
A  postgres-date@2.1.0
   no known CVEs
   surface: none
A  postgres-interval@1.2.0
   no known CVEs
   surface: none
A  postgres-interval@3.0.0
   no known CVEs
   surface: none
A  postgres-range@1.1.4
   no known CVEs
   surface: none
A  preact@10.24.3
   no known CVEs
   surface: none
A  preact-render-to-string@5.2.6
   no known CVEs
   surface: none
A  pretty-format@29.7.0
   no known CVEs
   surface: none
A  pretty-format@3.8.0
   no known CVEs
   surface: none
A  pretty-format@27.5.1
   no known CVEs
   surface: none
A  pretty-hrtime@1.0.3
   no known CVEs
   surface: none
A  pretty-ms@9.1.0
   no known CVEs
   surface: none
A  prism-react-renderer@2.4.1
   no known CVEs
   surface: none
A  prismock@1.35.3
   no known CVEs
   surface: none
A  process@0.11.10
   no known CVEs
   surface: none
A  process-nextick-args@2.0.1
   no known CVEs
   surface: none
A  progress@2.0.3
   no known CVEs
   surface: none
A  promise-inflight@1.0.1
   no known CVEs
   surface: none
A  promise-retry@2.0.1
   no known CVEs
   surface: none
A  prompts@2.4.2
   no known CVEs
   surface: none
A  property-information@7.0.0
   no known CVEs
   surface: none
A  proxy-addr@2.0.7
   no known CVEs
   surface: none
A  proxy-from-env@1.1.0
   no known CVEs
   surface: none
A  proxy-from-env@2.1.0
   no known CVEs
   surface: none
A  pseudomap@1.0.2
   no known CVEs
   surface: none
A  punycode@2.3.1
   no known CVEs
   surface: none
A  punycode.js@2.3.1
   no known CVEs
   surface: none
A  pure-rand@6.1.0
   no known CVEs
   surface: none
A  qr.js@0.0.0
   no known CVEs
   surface: none
A  qs-stringify@1.2.1
   no known CVEs
   surface: none
A  quansync@0.2.10
   no known CVEs
   surface: none
A  quansync@0.2.11
   no known CVEs
   surface: none
A  querystring@0.2.1
   no known CVEs
   surface: none
A  querystringify@2.2.0
   no known CVEs
   surface: none
A  queue@6.0.2
   no known CVEs
   surface: none
A  queue-microtask@1.2.3
   no known CVEs
   surface: none
A  quick-lru@4.0.1
   no known CVEs
   surface: none
A  range-parser@1.2.1
   no known CVEs
   surface: none
A  raw-body@2.5.2
   no known CVEs
   surface: none
A  raw-body@2.4.1
   no known CVEs
   surface: none
A  raw-body@3.0.2
   no known CVEs
   surface: none
A  raw-body@3.0.0
   no known CVEs
   surface: none
A  react@18.2.0
   no known CVEs
   surface: none
A  react@19.2.4
   no known CVEs
   surface: none
A  react-calendar@3.7.0
   no known CVEs
   surface: none
A  react-colorful@5.6.1
   no known CVEs
   surface: none
A  react-date-picker@8.4.0
   no known CVEs
   surface: none
A  react-day-picker@8.10.1
   no known CVEs
   surface: none
A  react-digit-input@2.1.0
   no known CVEs
   surface: none
A  react-dom@18.2.0
   no known CVEs
   surface: none
A  react-easy-crop@3.5.3
   no known CVEs
   surface: none
A  react-error-boundary@3.1.4
   no known CVEs
   surface: none
A  react-fit@1.4.0
   no known CVEs
   surface: none
A  react-from-dom@0.7.3
   no known CVEs
   surface: none
A  react-hook-form@7.43.3
   no known CVEs
   surface: none
A  react-i18next@12.3.1
   no known CVEs
   surface: none
A  react-is@16.13.1
   no known CVEs
   surface: none
A  react-is@18.2.0
   no known CVEs
   surface: none
A  react-is@17.0.2
   no known CVEs
   surface: none
A  react-live-chat-loader@2.8.1
   no known CVEs
   surface: none
A  react-qr-code@2.0.18
   no known CVEs
   surface: none
A  react-reconciler@0.26.2
   no known CVEs
   surface: none
A  react-reconciler@0.29.2
   no known CVEs
   surface: none
A  react-redux@9.2.0
   no known CVEs
   surface: none
A  react-refresh@0.18.0
   no known CVEs
   surface: none
A  react-remove-scroll@2.5.5
   no known CVEs
   surface: none
A  react-remove-scroll@2.5.4
   no known CVEs
   surface: none
A  react-remove-scroll-bar@2.3.3
   no known CVEs
   surface: none
A  react-schemaorg@2.0.0
   no known CVEs
   surface: none
A  react-select@5.8.0
   no known CVEs
   surface: none
A  react-sticky-box@2.0.4
   no known CVEs
   surface: none
A  react-style-singleton@2.2.1
   no known CVEs
   surface: none
A  react-timezone-select@1.4.0
   no known CVEs
   surface: none
A  react-transition-group@4.4.2
   no known CVEs
   surface: none
A  react-turnstile@1.1.3
   no known CVEs
   surface: none
A  react-universal-interface@0.6.2
   no known CVEs
   surface: none
A  react-use@17.6.0
   no known CVEs
   surface: none
A  react-use-intercom@5.5.0
   no known CVEs
   surface: none
A  react-virtual@2.10.4
   no known CVEs
   surface: none
A  read-cache@1.0.0
   no known CVEs
   surface: none
A  read-pkg@3.0.0
   no known CVEs
   surface: none
A  read-pkg@5.2.0
   no known CVEs
   surface: none
A  read-pkg-up@7.0.1
   no known CVEs
   surface: none
A  read-yaml-file@1.1.0
   no known CVEs
   surface: none
A  readable-stream@3.6.2
   no known CVEs
   surface: none
A  readable-stream@4.7.0
   no known CVEs
   surface: none
A  readdirp@4.1.2
   no known CVEs
   surface: none
A  readdirp@3.6.0
   no known CVEs
   surface: none
A  reading-time@1.5.0
   no known CVEs
   surface: none
A  recma-build-jsx@1.0.0
   no known CVEs
   surface: none
A  recma-jsx@1.0.1
   no known CVEs
   surface: none
A  recma-parse@1.0.0
   no known CVEs
   surface: none
A  recma-stringify@1.0.0
   no known CVEs
   surface: none
A  redent@3.0.0
   no known CVEs
   surface: none
A  redeyed@2.1.1
   no known CVEs
   surface: none
A  redis@4.7.0
   no known CVEs
   surface: none
A  redis-errors@1.2.0
   no known CVEs
   surface: none
A  redis-parser@3.0.0
   no known CVEs
   surface: none
A  redux@5.0.1
   no known CVEs
   surface: none
A  redux-thunk@3.1.0
   no known CVEs
   surface: none
A  reflect-metadata@0.1.14
   no known CVEs
   surface: none
A  reflect-metadata@0.2.2
   no known CVEs
   surface: none
A  reflect.getprototypeof@1.0.10
   no known CVEs
   surface: none
A  regenerator-runtime@0.13.9
   no known CVEs
   surface: none
A  regex@6.1.0
   no known CVEs
   surface: none
A  regex-recursion@6.0.2
   no known CVEs
   surface: none
A  regex-utilities@2.3.0
   no known CVEs
   surface: none
A  regexp-to-ast@0.5.0
   no known CVEs
   surface: none
A  regexp.prototype.flags@1.5.4
   no known CVEs
   surface: none
A  rehype-katex@7.0.1
   no known CVEs
   surface: none
A  rehype-parse@9.0.1
   no known CVEs
   surface: none
A  rehype-pretty-code@0.14.1
   no known CVEs
   surface: none
A  rehype-raw@7.0.0
   no known CVEs
   surface: none
A  rehype-recma@1.0.0
   no known CVEs
   surface: none
A  rehype-stringify@10.0.1
   no known CVEs
   surface: none
A  reinterval@1.1.0
   no known CVEs
   surface: none
A  remark-disable-tokenizers@1.1.1
   no known CVEs
   surface: none
A  remark-frontmatter@5.0.0
   no known CVEs
   surface: none
A  remark-gfm@4.0.1
   no known CVEs
   surface: none
A  remark-math@6.0.0
   no known CVEs
   surface: none
A  remark-mdx@3.1.1
   no known CVEs
   surface: none
A  remark-mdx-frontmatter@5.2.0
   no known CVEs
   surface: none
A  remark-parse@11.0.0
   no known CVEs
   surface: none
A  remark-reading-time@2.1.0
   no known CVEs
   surface: none
A  remark-rehype@11.1.2
   no known CVEs
   surface: none
A  remark-smartypants@3.0.2
   no known CVEs
   surface: none
A  remark-stringify@11.0.0
   no known CVEs
   surface: none
A  remedial@1.0.8
   no known CVEs
   surface: none
A  remove-markdown@0.5.0
   no known CVEs
   surface: none
A  remove-trailing-separator@1.1.0
   no known CVEs
   surface: none
A  remove-trailing-spaces@1.0.9
   no known CVEs
   surface: none
A  repeat-string@1.6.1
   no known CVEs
   surface: none
A  require-from-string@2.0.2
   no known CVEs
   surface: none
A  require-main-filename@2.0.0
   no known CVEs
   surface: none
A  reselect@5.1.1
   no known CVEs
   surface: none
A  resize-observer-polyfill@1.5.1
   no known CVEs
   surface: none
A  resolve-cwd@3.0.0
   no known CVEs
   surface: none
A  resolve-from@5.0.0
   no known CVEs
   surface: none
A  resolve-from@4.0.0
   no known CVEs
   surface: none
A  resolve.exports@2.0.2
   no known CVEs
   surface: none
A  restore-cursor@3.1.0
   no known CVEs
   surface: none
A  restore-cursor@4.0.0
   no known CVEs
   surface: none
A  restore-cursor@5.1.0
   no known CVEs
   surface: none
A  retell-client-js-sdk@2.0.7
   no known CVEs
   surface: none
A  retext@9.0.0
   no known CVEs
   surface: none
A  retext-latin@4.0.0
   no known CVEs
   surface: none
A  retext-smartypants@6.2.0
   no known CVEs
   surface: none
A  retext-stringify@4.0.0
   no known CVEs
   surface: none
A  reusify@1.0.4
   no known CVEs
   surface: none
A  rfdc@1.4.1
   no known CVEs
   surface: none
A  ripemd160@2.0.2
   no known CVEs
   surface: none
A  robust-predicates@3.0.3
   no known CVEs
   surface: none
A  roughjs@4.6.6
   no known CVEs
   surface: none
A  rrule@2.7.1
   no known CVEs
   surface: none
A  rrule@2.6.4
   no known CVEs
   surface: none
A  rrweb-cssom@0.6.0
   no known CVEs
   surface: none
A  rrweb-cssom@0.8.0
   no known CVEs
   surface: none
A  rrweb-cssom@0.7.1
   no known CVEs
   surface: none
A  rtl-css-js@1.16.1
   no known CVEs
   surface: none
A  run-async@2.4.1
   no known CVEs
   surface: none
A  run-async@3.0.0
   no known CVEs
   surface: none
A  run-exclusive@2.2.19
   no known CVEs
   surface: none
A  run-parallel@1.2.0
   no known CVEs
   surface: none
A  safe-array-concat@1.1.3
   no known CVEs
   surface: none
A  safe-buffer@5.2.1
   no known CVEs
   surface: none
A  safe-buffer@5.1.2
   no known CVEs
   surface: none
A  safe-push-apply@1.0.0
   no known CVEs
   surface: none
A  safe-regex-test@1.1.0
   no known CVEs
   surface: none
A  safe-stable-stringify@2.4.3
   no known CVEs
   surface: none
A  sax@1.4.3
   no known CVEs
   surface: none
A  sax@1.6.0
   no known CVEs
   surface: none
A  saxes@6.0.0
   no known CVEs
   surface: none
A  scheduler@0.23.2
   no known CVEs
   surface: none
A  scheduler@0.20.2
   no known CVEs
   surface: none
A  schema-dts@1.1.0
   no known CVEs
   surface: none
A  schema-utils@4.3.3
   no known CVEs
   surface: none
A  schema-utils@3.3.0
   no known CVEs
   surface: none
A  screenfull@5.2.0
   no known CVEs
   surface: none
A  scroll-into-view-if-needed@3.1.0
   no known CVEs
   surface: none
A  scuid@1.1.0
   no known CVEs
   surface: none
A  sdp@3.2.1
   no known CVEs
   surface: none
A  section-matter@1.0.0
   no known CVEs
   surface: none
A  secure-json-parse@2.7.0
   no known CVEs
   surface: none
A  send@1.2.0
   no known CVEs
   surface: none
A  send@0.19.0
   no known CVEs
   surface: none
A  sentence-case@1.1.3
   no known CVEs
   surface: none
A  sentence-case@3.0.4
   no known CVEs
   surface: none
A  seq-queue@0.0.5
   no known CVEs
   surface: none
A  sequin@0.1.1
   no known CVEs
   surface: none
A  serve-static@2.2.0
   no known CVEs
   surface: none
A  serve-static@1.16.2
   no known CVEs
   surface: none
A  server-only@0.0.1
   no known CVEs
   surface: none
A  set-blocking@2.0.0
   no known CVEs
   surface: none
A  set-function-length@1.2.2
   no known CVEs
   surface: none
A  set-function-name@2.0.2
   no known CVEs
   surface: none
A  set-harmonic-interval@1.0.1
   no known CVEs
   surface: none
A  set-proto@1.0.0
   no known CVEs
   surface: none
A  setprototypeof@1.2.0
   no known CVEs
   surface: none
A  setprototypeof@1.1.1
   no known CVEs
   surface: none
A  shebang-command@2.0.0
   no known CVEs
   surface: none
A  shebang-command@1.2.0
   no known CVEs
   surface: none
A  shebang-regex@3.0.0
   no known CVEs
   surface: none
A  shebang-regex@1.0.0
   no known CVEs
   surface: none
A  shimmer@1.2.1
   no known CVEs
   surface: none
A  short-uuid@4.2.0
   no known CVEs
   surface: none
A  side-channel@1.1.0
   no known CVEs
   surface: none
A  side-channel-list@1.0.0
   no known CVEs
   surface: none
A  side-channel-map@1.0.1
   no known CVEs
   surface: none
A  side-channel-weakmap@1.0.2
   no known CVEs
   surface: none
A  siginfo@2.0.0
   no known CVEs
   surface: none
A  signal-exit@3.0.7
   no known CVEs
   surface: none
A  signal-exit@4.1.0
   no known CVEs
   surface: none
A  signedsource@1.0.0
   no known CVEs
   surface: none
A  simple-concat@1.0.1
   no known CVEs
   surface: none
A  simple-swizzle@0.2.2
   no known CVEs
   surface: none
A  siphash@1.1.0
   no known CVEs
   surface: none
A  sirv@2.0.4
   no known CVEs
   surface: none
A  sisteransi@1.0.5
   no known CVEs
   surface: none
A  slash@3.0.0
   no known CVEs
   surface: none
A  slash@5.1.0
   no known CVEs
   surface: none
A  slice-ansi@4.0.0
   no known CVEs
   surface: none
A  slice-ansi@3.0.0
   no known CVEs
   surface: none
A  slice-ansi@6.0.0
   no known CVEs
   surface: none
A  slice-ansi@7.1.0
   no known CVEs
   surface: none
A  slice-ansi@5.0.0
   no known CVEs
   surface: none
A  slug@6.1.0
   no known CVEs
   surface: none
A  smart-buffer@4.2.0
   no known CVEs
   surface: none
A  snake-case@1.1.2
   no known CVEs
   surface: none
A  snake-case@3.0.4
   no known CVEs
   surface: none
A  socket.io-parser@4.2.6
   no known CVEs
   surface: none
A  sonner@1.7.4
   no known CVEs
   surface: none
A  sorted-array-functions@1.3.0
   no known CVEs
   surface: none
A  source-map@0.6.1
   no known CVEs
   surface: none
A  source-map@0.5.6
   no known CVEs
   surface: none
A  source-map@0.5.7
   no known CVEs
   surface: none
A  space-separated-tokens@2.0.2
   no known CVEs
   surface: none
A  sparse-bitfield@3.0.3
   no known CVEs
   surface: none
A  spawndamnit@3.0.1
   no known CVEs
   surface: none
A  spdx-correct@3.1.1
   no known CVEs
   surface: none
A  spdx-exceptions@2.3.0
   no known CVEs
   surface: none
A  spdx-expression-parse@3.0.1
   no known CVEs
   surface: none
A  spdx-license-ids@3.0.11
   no known CVEs
   surface: none
A  split2@3.2.2
   no known CVEs
   surface: none
A  split2@4.1.0
   no known CVEs
   surface: none
A  sponge-case@1.0.1
   no known CVEs
   surface: none
A  sprintf-js@1.1.3
   no known CVEs
   surface: none
A  sprintf-js@1.0.3
   no known CVEs
   surface: none
A  sql-highlight@6.0.0
   no known CVEs
   surface: none
A  sqlstring@2.3.3
   no known CVEs
   surface: none
A  ssri@9.0.1
   no known CVEs
   surface: none
A  ssri@8.0.1
   no known CVEs
   surface: none
A  ssri@10.0.6
   no known CVEs
   surface: none
A  stack-generator@2.0.10
   no known CVEs
   surface: none
A  stack-trace@0.0.10
   no known CVEs
   surface: none
A  stack-utils@2.0.6
   no known CVEs
   surface: none
A  stackback@0.0.2
   no known CVEs
   surface: none
A  stackframe@1.3.4
   no known CVEs
   surface: none
A  stacktrace-parser@0.1.10
   no known CVEs
   surface: none
A  standard-as-callback@2.1.0
   no known CVEs
   surface: none
A  statuses@2.0.1
   no known CVEs
   surface: none
A  statuses@1.5.0
   no known CVEs
   surface: none
A  statuses@2.0.2
   no known CVEs
   surface: none
A  std-env@3.10.0
   no known CVEs
   surface: none
A  stdin-discarder@0.2.2
   no known CVEs
   surface: none
A  stop-iteration-iterator@1.1.0
   no known CVEs
   surface: none
A  stream-shift@1.0.1
   no known CVEs
   surface: none
A  streamsearch@1.1.0
   no known CVEs
   surface: none
A  strict-event-emitter@0.5.1
   no known CVEs
   surface: none
A  string_decoder@1.3.0
   no known CVEs
   surface: none
A  string-argv@0.3.2
   no known CVEs
   surface: none
A  string-env-interpolation@1.0.1
   no known CVEs
   surface: none
A  string-length@4.0.2
   no known CVEs
   surface: none
A  string-width@4.2.3
   no known CVEs
   surface: none
A  string-width@5.1.2
   no known CVEs
   surface: none
A  string-width@7.2.0
   no known CVEs
   surface: none
A  string.prototype.codepointat@0.2.1
   no known CVEs
   surface: none
A  string.prototype.padend@3.1.6
   no known CVEs
   surface: none
A  string.prototype.trim@1.2.10
   no known CVEs
   surface: none
A  string.prototype.trimend@1.0.9
   no known CVEs
   surface: none
A  string.prototype.trimstart@1.0.8
   no known CVEs
   surface: none
A  stringify-entities@4.0.4
   no known CVEs
   surface: none
A  strip-ansi@6.0.1
   no known CVEs
   surface: none
A  strip-ansi@7.1.0
   no known CVEs
   surface: none
A  strip-bom@3.0.0
   no known CVEs
   surface: none
A  strip-bom@4.0.0
   no known CVEs
   surface: none
A  strip-bom-string@1.0.0
   no known CVEs
   surface: none
A  strip-final-newline@2.0.0
   no known CVEs
   surface: none
A  strip-final-newline@4.0.0
   no known CVEs
   surface: none
A  strip-final-newline@3.0.0
   no known CVEs
   surface: none
A  strip-indent@3.0.0
   no known CVEs
   surface: none
A  strip-json-comments@3.1.1
   no known CVEs
   surface: none
A  strip-json-comments@2.0.1
   no known CVEs
   surface: none
A  stripe-event-types@3.1.0
   no known CVEs
   surface: none
A  strnum@2.2.3
   no known CVEs
   surface: none
A  strtok3@10.3.4
   no known CVEs
   surface: none
A  style-to-js@1.1.21
   no known CVEs
   surface: none
A  style-to-object@1.0.14
   no known CVEs
   surface: none
A  stylehacks@7.0.7
   no known CVEs
   surface: none
A  stylis@4.0.13
   no known CVEs
   surface: none
A  stylis@4.3.1
   no known CVEs
   surface: none
A  stylis@4.3.6
   no known CVEs
   surface: none
A  superjson@1.9.1
   no known CVEs
   surface: none
A  superjson@2.2.5
   no known CVEs
   surface: none
A  supports-color@8.1.1
   no known CVEs
   surface: none
A  supports-color@10.2.2
   no known CVEs
   surface: none
A  supports-color@7.2.0
   no known CVEs
   surface: none
A  supports-color@5.5.0
   no known CVEs
   surface: none
A  supports-color@9.2.2
   no known CVEs
   surface: none
A  supports-hyperlinks@2.3.0
   no known CVEs
   surface: none
A  supports-preserve-symlinks-flag@1.0.0
   no known CVEs
   surface: none
A  swap-case@2.0.2
   no known CVEs
   surface: none
A  swap-case@1.1.2
   no known CVEs
   surface: none
A  symbol-observable@4.0.0
   no known CVEs
   surface: none
A  symbol-tree@3.2.4
   no known CVEs
   surface: none
A  tabbable@6.4.0
   no known CVEs
   surface: none
A  tabbable@6.3.0
   no known CVEs
   surface: none
A  tailwind-merge@1.13.2
   no known CVEs
   surface: none
A  tailwind-scrollbar@4.0.2
   no known CVEs
   surface: none
A  tailwindcss@4.1.17
   no known CVEs
   surface: none
A  tailwindcss@4.1.15
   no known CVEs
   surface: none
A  tailwindcss@4.1.16
   no known CVEs
   surface: none
A  tailwindcss-radix@4.0.2
   no known CVEs
   surface: none
A  tarn@3.0.2
   no known CVEs
   surface: none
A  tdigest@0.1.2
   no known CVEs
   surface: none
A  test-exclude@6.0.0
   no known CVEs
   surface: none
A  text-hex@1.0.0
   no known CVEs
   surface: none
A  thenby@1.3.4
   no known CVEs
   surface: none
A  thenify@3.3.1
   no known CVEs
   surface: none
A  thenify-all@1.6.0
   no known CVEs
   surface: none
A  third-party-capital@1.0.20
   no known CVEs
   surface: none
A  thirty-two@1.0.2
   no known CVEs
   surface: none
A  throttle-debounce@3.0.1
   no known CVEs
   surface: none
A  throttleit@2.1.0
   no known CVEs
   surface: none
A  through@2.3.8
   no known CVEs
   surface: none
A  timeout-signal@2.0.0
   no known CVEs
   surface: none
A  timezone-soft@1.3.1
   no known CVEs
   surface: none
A  timm@1.7.1
   no known CVEs
   surface: none
A  tiny-inflate@1.0.3
   no known CVEs
   surface: none
A  tiny-invariant@1.3.3
   no known CVEs
   surface: none
A  tiny-warning@1.0.3
   no known CVEs
   surface: none
A  tinybench@2.9.0
   no known CVEs
   surface: none
A  tinycolor2@1.4.2
   no known CVEs
   surface: none
A  tinyglobby@0.2.15
   no known CVEs
   surface: none
A  tinyglobby@0.2.16
   no known CVEs
   surface: none
A  tinygradient@1.1.5
   no known CVEs
   surface: none
A  tinyrainbow@3.0.3
   no known CVEs
   surface: none
A  title-case@3.0.3
   no known CVEs
   surface: none
A  title-case@1.1.2
   no known CVEs
   surface: none
A  to-buffer@1.2.2
   no known CVEs
   surface: none
A  to-regex-range@5.0.1
   no known CVEs
   surface: none
A  toad-cache@3.7.0
   no known CVEs
   surface: none
A  toggle-selection@1.0.6
   no known CVEs
   surface: none
A  toidentifier@1.0.1
   no known CVEs
   surface: none
A  toidentifier@1.0.0
   no known CVEs
   surface: none
A  token-types@6.1.1
   no known CVEs
   surface: none
A  toml@3.0.0
   no known CVEs
   surface: none
A  toposort@2.0.2
   no known CVEs
   surface: none
A  totalist@3.0.1
   no known CVEs
   surface: none
A  tough-cookie@4.1.4
   no known CVEs
   surface: none
A  tr46@4.1.1
   no known CVEs
   surface: none
A  tr46@0.0.3
   no known CVEs
   surface: none
A  tr46@5.1.1
   no known CVEs
   surface: none
A  trim-lines@3.0.1
   no known CVEs
   surface: none
A  trim-newlines@3.0.1
   no known CVEs
   surface: none
A  triple-beam@1.4.1
   no known CVEs
   surface: none
A  trough@2.2.0
   no known CVEs
   surface: none
A  trouter@2.0.1
   no known CVEs
   surface: none
A  ts-debounce@4.0.0
   no known CVEs
   surface: none
A  ts-dedent@2.2.0
   no known CVEs
   surface: none
A  ts-easing@0.2.0
   no known CVEs
   surface: none
A  ts-essentials@10.0.2
   no known CVEs
   surface: none
A  ts-interface-checker@0.1.13
   no known CVEs
   surface: none
A  ts-log@2.2.7
   no known CVEs
   surface: none
A  tsafe@1.8.12
   no known CVEs
   surface: none
A  tslib@2.8.1
   no known CVEs
   surface: none
A  tslib@2.0.1
   no known CVEs
   surface: none
A  tslib@1.14.1
   no known CVEs
   surface: none
A  tslib@2.6.3
   no known CVEs
   surface: none
A  tslog@4.9.2
   no known CVEs
   surface: none
A  turbo-darwin-arm64@2.7.1
   no known CVEs
   surface: none
A  turndown@7.2.0
   no known CVEs
   surface: none
A  tw-animate-css@1.4.0
   no known CVEs
   surface: none
A  twoslash@0.3.7
   no known CVEs
   surface: none
A  twoslash-protocol@0.3.7
   no known CVEs
   surface: none
A  type-detect@4.0.8
   no known CVEs
   surface: none
A  type-fest@0.12.0
   no known CVEs
   surface: none
A  type-fest@0.7.1
   no known CVEs
   surface: none
A  type-fest@0.8.1
   no known CVEs
   surface: none
A  type-fest@0.6.0
   no known CVEs
   surface: none
A  type-fest@4.34.1
   no known CVEs
   surface: none
A  type-fest@0.18.1
   no known CVEs
   surface: none
A  type-fest@0.3.1
   no known CVEs
   surface: none
A  type-fest@0.15.1
   no known CVEs
   surface: none
A  type-fest@0.21.3
   no known CVEs
   surface: none
A  type-is@1.6.18
   no known CVEs
   surface: none
A  type-is@2.0.1
   no known CVEs
   surface: none
A  typed-array-buffer@1.0.3
   no known CVEs
   surface: none
A  typed-array-byte-length@1.0.3
   no known CVEs
   surface: none
A  typed-array-byte-offset@1.0.4
   no known CVEs
   surface: none
A  typed-array-length@1.0.7
   no known CVEs
   surface: none
A  typed-emitter@2.1.0
   no known CVEs
   surface: none
A  typedarray@0.0.6
   no known CVEs
   surface: none
A  uc.micro@2.1.0
   no known CVEs
   surface: none
A  ufo@1.6.1
   no known CVEs
   surface: none
A  ufo@1.6.3
   no known CVEs
   surface: none
A  uid@2.0.2
   no known CVEs
   surface: none
A  uint8array-extras@1.5.0
   no known CVEs
   surface: none
A  unbox-primitive@1.1.0
   no known CVEs
   surface: none
A  unc-path-regex@0.1.2
   no known CVEs
   surface: none
A  uncrypto@0.1.3
   no known CVEs
   surface: none
A  undici-types@6.19.8
   no known CVEs
   surface: none
A  unicode-trie@2.0.0
   no known CVEs
   surface: none
A  unified@11.0.5
   no known CVEs
   surface: none
A  unique-filename@2.0.1
   no known CVEs
   surface: none
A  unique-filename@1.1.1
   no known CVEs
   surface: none
A  unique-filename@3.0.0
   no known CVEs
   surface: none
A  unique-slug@3.0.0
   no known CVEs
   surface: none
A  unique-slug@2.0.2
   no known CVEs
   surface: none
A  unique-slug@4.0.0
   no known CVEs
   surface: none
A  unist-util-find-after@5.0.0
   no known CVEs
   surface: none
A  unist-util-is@6.0.0
   no known CVEs
   surface: none
A  unist-util-mdx-define@1.1.2
   no known CVEs
   surface: none
A  unist-util-modify-children@4.0.0
   no known CVEs
   surface: none
A  unist-util-position@5.0.0
   no known CVEs
   surface: none
A  unist-util-position-from-estree@2.0.0
   no known CVEs
   surface: none
A  unist-util-remove@4.0.0
   no known CVEs
   surface: none
A  unist-util-remove-position@5.0.0
   no known CVEs
   surface: none
A  unist-util-stringify-position@4.0.0
   no known CVEs
   surface: none
A  unist-util-visit@5.0.0
   no known CVEs
   surface: none
A  unist-util-visit-children@3.0.0
   no known CVEs
   surface: none
A  unist-util-visit-parents@6.0.1
   no known CVEs
   surface: none
A  universal-github-app-jwt@2.2.2
   no known CVEs
   surface: none
A  universal-user-agent@7.0.3
   no known CVEs
   surface: none
A  universalify@2.0.1
   no known CVEs
   surface: none
A  universalify@0.2.0
   no known CVEs
   surface: none
A  universalify@0.1.2
   no known CVEs
   surface: none
A  unixify@1.0.0
   no known CVEs
   surface: none
A  unpipe@1.0.0
   no known CVEs
   surface: none
A  update-input-width@1.4.2
   no known CVEs
   surface: none
A  upper-case@1.1.3
   no known CVEs
   surface: none
A  upper-case@2.0.2
   no known CVEs
   surface: none
A  upper-case-first@2.0.2
   no known CVEs
   surface: none
A  upper-case-first@1.1.2
   no known CVEs
   surface: none
A  url-template@2.0.8
   no known CVEs
   surface: none
A  use-callback-ref@1.3.1
   no known CVEs
   surface: none
A  use-isomorphic-layout-effect@1.1.2
   no known CVEs
   surface: none
A  use-sidecar@1.1.2
   no known CVEs
   surface: none
A  use-sync-external-store@1.6.0
   no known CVEs
   surface: none
A  use-sync-external-store@1.2.0
   no known CVEs
   surface: none
A  utif@2.0.1
   no known CVEs
   surface: none
A  util-deprecate@1.0.2
   no known CVEs
   surface: none
A  utils-merge@1.0.1
   no known CVEs
   surface: none
A  v8-to-istanbul@9.2.0
   no known CVEs
   surface: none
A  validate-npm-package-license@3.0.4
   no known CVEs
   surface: none
A  vary@1.1.2
   no known CVEs
   surface: none
A  vfile@6.0.3
   no known CVEs
   surface: none
A  vfile-location@5.0.3
   no known CVEs
   surface: none
A  vfile-message@4.0.2
   no known CVEs
   surface: none
A  victory-vendor@37.3.6
   no known CVEs
   surface: none
A  vite-plugin-environment@1.1.3
   no known CVEs
   surface: none
A  vitest-fetch-mock@0.4.5
   no known CVEs
   surface: none
A  vitest-mock-extended@3.1.0
   no known CVEs
   surface: none
A  void-elements@3.1.0
   no known CVEs
   surface: none
A  vscode-languageserver-protocol@3.17.5
   no known CVEs
   surface: none
A  vscode-languageserver-textdocument@1.0.12
   no known CVEs
   surface: none
A  vscode-languageserver-types@3.17.5
   no known CVEs
   surface: none
A  w3c-xmlserializer@4.0.0
   no known CVEs
   surface: none
A  w3c-xmlserializer@5.0.0
   no known CVEs
   surface: none
A  walker@1.0.8
   no known CVEs
   surface: none
A  watchpack@2.5.1
   no known CVEs
   surface: none
A  wcwidth@1.0.1
   no known CVEs
   surface: none
A  web-namespaces@2.0.1
   no known CVEs
   surface: none
A  web-streams-polyfill@4.0.0-beta.3
   no known CVEs
   surface: none
A  web-streams-polyfill@3.3.3
   no known CVEs
   surface: none
A  web-vitals@4.2.4
   no known CVEs
   surface: none
A  webidl-conversions@7.0.0
   no known CVEs
   surface: none
A  webidl-conversions@3.0.1
   no known CVEs
   surface: none
A  webpack-node-externals@3.0.0
   no known CVEs
   surface: none
A  webpack-sources@3.3.4
   no known CVEs
   surface: none
A  webpack-sources@3.2.3
   no known CVEs
   surface: none
A  webpack-virtual-modules@0.5.0
   no known CVEs
   surface: none
A  webpack-virtual-modules@0.6.2
   no known CVEs
   surface: none
A  whatwg-encoding@2.0.0
   no known CVEs
   surface: none
A  whatwg-encoding@3.1.1
   no known CVEs
   surface: none
A  whatwg-mimetype@4.0.0
   no known CVEs
   surface: none
A  whatwg-mimetype@3.0.0
   no known CVEs
   surface: none
A  which-boxed-primitive@1.1.1
   no known CVEs
   surface: none
A  which-builtin-type@1.2.1
   no known CVEs
   surface: none
A  which-collection@1.0.2
   no known CVEs
   surface: none
A  which-module@2.0.1
   no known CVEs
   surface: none
A  which-typed-array@1.1.19
   no known CVEs
   surface: none
A  wicked-good-xpath@1.3.0
   no known CVEs
   surface: none
A  wide-align@1.1.5
   no known CVEs
   surface: none
A  widest-line@3.1.0
   no known CVEs
   surface: none
A  widest-line@4.0.1
   no known CVEs
   surface: none
A  windows-iana@5.1.0
   no known CVEs
   surface: none
A  winston-transport@4.9.0
   no known CVEs
   surface: none
A  wonka@6.3.5
   no known CVEs
   surface: none
A  wordwrap@1.0.0
   no known CVEs
   surface: none
A  wrap-ansi@7.0.0
   no known CVEs
   surface: none
A  wrap-ansi@6.2.0
   no known CVEs
   surface: none
A  wrap-ansi@9.0.0
   no known CVEs
   surface: none
A  wrap-ansi@8.1.0
   no known CVEs
   surface: none
A  wrappy@1.0.2
   no known CVEs
   surface: none
A  wsl-utils@0.1.0
   no known CVEs
   surface: none
A  xcase@2.0.1
   no known CVEs
   surface: none
A  xdg-app-paths@8.3.0
   no known CVEs
   surface: none
A  xdg-portable@10.6.0
   no known CVEs
   surface: none
A  xhr@2.6.0
   no known CVEs
   surface: none
A  xliff@6.2.2
   no known CVEs
   surface: none
A  xml-crypto@6.1.2
   no known CVEs
   surface: none
A  xml-encryption@3.1.0
   no known CVEs
   surface: none
A  xml-name-validator@4.0.0
   no known CVEs
   surface: none
A  xml-name-validator@5.0.0
   no known CVEs
   surface: none
A  xml-parse-from-string@1.0.1
   no known CVEs
   surface: none
A  xmlbuilder@11.0.1
   no known CVEs
   surface: none
A  xmlbuilder@15.1.1
   no known CVEs
   surface: none
A  xmlchars@2.2.0
   no known CVEs
   surface: none
A  xpath@0.0.33
   no known CVEs
   surface: none
A  xpath@0.0.32
   no known CVEs
   surface: none
A  xpath@0.0.34
   no known CVEs
   surface: none
A  xtend@4.0.2
   no known CVEs
   surface: none
A  yallist@4.0.0
   no known CVEs
   surface: none
A  yallist@5.0.0
   no known CVEs
   surface: none
A  yallist@2.1.2
   no known CVEs
   surface: none
A  yallist@3.1.1
   no known CVEs
   surface: none
A  yn@3.1.1
   no known CVEs
   surface: none
A  yocto-queue@0.1.0
   no known CVEs
   surface: none
A  yocto-queue@1.2.1
   no known CVEs
   surface: none
A  yoctocolors@2.1.1
   no known CVEs
   surface: none
A  yoctocolors-cjs@2.1.3
   no known CVEs
   surface: none
A  yup@0.32.11
   no known CVEs
   surface: none
A  zod-error@1.5.0
   no known CVEs
   surface: none
A  zod-validation-error@1.5.0
   no known CVEs
   surface: none
A  zustand@4.5.2
   no known CVEs
   surface: none
A  zwitch@2.0.4
   no known CVEs
   surface: none

Note what the score can and cannot say. dompurify's card is quiet on the surface axis and loud on CVEs; axios is loud on both. Which of the deck's 90 advisory-carrying packages your build actually ships, and whether any of the code behind them can come out, is not a scoring question — it took the run below to answer.

The run

The full from-zero run — inventory through packed artifact, all stages — took 70 minutes on one machine, unattended. That time is paid when dependencies change, not on every commit: builds consume the stored artifact, a PR is a one-second fingerprint check, and a version bump revalidates just the dependency that moved. Of the 232 runtime dependencies, 174 were extracted down to what Cal's code reaches, 38 were pruned conservatively but kept complete, and 20 shipped as pinned stock. All 212 hardened dependencies were overlaid at once and the gate passed: full suite differential, zero new failures, plus a production build run from scratch, with no build cache to lean on.

installedshippedchange
dependencies232174 extracted + 38 pruned + 20 pinned stockall update-gated
files, validated extractions24,2731,074−95.6%
bytes, validated extractions136.7 MB43.7 MB−68.0%

The deploy side has its own measured result, from a burn-in four days earlier: apply the artifact, run the production build, then strip the development-only build twins and non-runtime files (type declarations, source maps, docs; licenses always kept). The served node_modules went from 3.3 GB to 2.0 GB with build, boot, and the login e2e green, and zero strip-induced regressions.

The CVEs

The installed tree carried 189 advisories. After hardening, each has a verdict backed by what's actually in the artifact:

verdictcountmeaning here
not shipped103the affected package or version never enters the artifact — almost always dev or build tooling (test runners, bundlers, linters) that production never needs; that's where most advisories live
eliminated1vulnerable code proven dead and removed; build + suite pass without it
reached48Cal really runs this code; the fix is upgrading, not removal
unresolved37advisory too coarse to map to a symbol; disclosed, not cleared

The elimination is the start-ui-web shape at monorepo scale. glob's HIGH advisory (GHSA-5j98) lives in the package's command-line entry, dist/esm/bin.mjs — a script nothing in Cal ever imports; glob is there for its library API. The run pruned the file, the advisory's code is provably absent from the artifact, and the suite plus the from-scratch production build passed without it. In earlier runs glob couldn't even be extracted — the build gate rejected its overlay and pinned it whole. Evidence accumulated, and the verdict moved.

The count could be eight, and stays one. The seven advisories an aggressive mode would add sit behind reachable-but-unexecuted functions; stubbing those would crash production the first time an error path called one — nodemailer's own compose path calls the setRaw() sink internally, for instance. Held-by-default ships them pinned and update-gated, and their CVEs count as reached or unresolved. The run still removes proven-dead code across 18 advisory-carrying dependencies; the glob removal is the one where the proof reached the advisory itself.

The 48 reached advisories concentrate where you'd guess: 27 in axios, 6 in nodemailer, 4 in dompurify. That code runs in production, so the answer is an upgrade, and the report says exactly that.

The work

steptime
cold score on the checkout~3 min
config file (104 lines, monorepo + e2e wiring)one sitting
chainstrip run, zero to artifact70 min, unattended
coverage --prompt writes the work order~2 min
agent drafting session off it (15 deps), human reviewone sitting; not clocked
witness campaign, connected~1 h, unattended
ongoing, per PR~1 s, automatic

The run's coverage data doubles as a to-do list: every under-tested dependency, ranked, with the functions in Cal's own code that call it — the worklist. Two paths lead out of it, and both ran here. The test path: coverage --prompt emitted one ranked work order; a coding agent drafted tests off it in a single session, covering 15 dependencies — and surfaced two real bugs in how Cal uses its dependencies. One: Cal's phone-format helper promises to return unparsable input unchanged, but the library call above the fallback throws first, so the graceful path can never fire. Two: a -1 "no credential" placeholder is truthy in JavaScript, so users without the payment app installed were shown its connect flow. The tests document both defects; the fixes stay Cal's to make. That is what asserting tests buy that no probe can: they check the usage is right, not just that code ran.

The machine legs are not instant, and the table means its words: the three campaigns completed since the witness stage was reworked measured 59, 108, and 60 minutes, all unattended — the latest (2026-07-29, five batches, 40 probes over 45 targets) is the report on disk. The early campaigns ran longer: multi-hour on 2026-07-20, where a mid-run network death and clean resume produced the built-in retry, and one 2026-07-27 run over two hours on a since-fixed bug. Unattended is the operative word: the human cost of the probe path is reviewing what comes back, not sitting through it.

The probe path took the tail: dependency code that carried no execution evidence at all — no test, no build step, no e2e pass had ever run it. The campaign generated probes to make Cal's own code paths run it, graded them against the hardened build, and kept the evidence — moving 41 dependencies from pinned whole, as npm shipped them, to validated minimum-surface extractions. The probes themselves are archived in ChainStrip's state, never merged into Cal's suite.

All four artifacts of that work are below, in full. The worklist as it prints today:

the coverage worklist — full real output (printed 2026-07-29; scroll inside)
$ chainstrip coverage --callers

whole-suite coverage gap — 119 deps measured · median 36% of functions executed
  0–25%: 39 · 25–50%: 42 · 50–75%: 26 · 75–100%: 12
  34 extracted deps no test loads at all

⚠ = vulnerable AND under-tested (live CVE + low coverage) — TEST THESE FIRST.

LEAST-COVERED — under-tested deps and YOUR functions that use them (write tests for those):
   38%  next-auth  ⚠ 3 live CVEs (CRITICAL)  (418/1096 fns run, 678 never run, 1 file(s) never loaded) · e.g. $, A, AccountNotLinkedError2, AsyncIterator…
          apps/web/app/(use-page-wrapper)/auth/forgot-password/page.tsx → ServerPage
          apps/web/app/(use-page-wrapper)/settings/(settings-layout)/SettingsLayoutAppDirClient.tsx → useTabs
          apps/web/app/providers.tsx → Providers
          apps/web/components/apps/btcpayserver/Setup.tsx → BTCPaySetupPage
          apps/web/components/apps/hitpay/Setup.tsx → HitPaySetupPage
          apps/web/components/setup/AdminUser.tsx → (anonymous)
          apps/web/components/ui/UsernameAvailability/PremiumTextfield.tsx → PremiumTextfield
          apps/web/components/ui/UsernameAvailability/UsernameTextfield.tsx → UsernameTextfield
          apps/web/lib/app-providers.tsx → CustomI18nextProvider
          apps/web/modules/apps/[slug]/setup/setup-view.tsx → SetupInformation
          apps/web/modules/auth/hooks/useRedirectToLoginIfUnauthenticated.tsx → useRedirectToLoginIfUnauthenticated
          apps/web/modules/auth/login-view.tsx → onClick, onSubmit
          apps/web/modules/auth/logout-view.tsx → Logout
          apps/web/modules/auth/oauth2/authorize-view.tsx → Authorize
          apps/web/modules/auth/signin-view.tsx → onClick
          apps/web/modules/auth/verify-email-change-view.tsx → VerifyEmailChange
          apps/web/modules/auth/verify-email-view.tsx → VerifyEmailPage, onClick
          apps/web/modules/auth/verify-view.tsx → sendVerificationLogin
          apps/web/modules/bookings/components/BookerWebWrapper.tsx → BookerWebWrapperComponent
          apps/web/modules/bookings/hooks/useEventTypes.ts → useEventTypes
          apps/web/modules/bookings/hooks/useVerifyEmail.ts → useVerifyEmail
          apps/web/modules/bookings/views/bookings-single-view.tsx → Success
          apps/web/modules/connect-and-join/connect-and-join-view.tsx → ConnectAndJoin
          apps/web/modules/data-table/components/segment/DuplicateSegmentDialog.tsx → DuplicateSegmentDialog
          apps/web/modules/data-table/components/segment/FilterSegmentSelect.tsx → FilterSegmentSelect
          apps/web/modules/data-table/components/segment/SaveFilterSegmentButton.tsx → SaveFilterSegmentButton
          apps/web/modules/embed/components/Embed.tsx → EmbedTypeCodeAndPreviewDialogContent
          apps/web/modules/event-types/components/locations/HostLocations.tsx → HostLocations
          apps/web/modules/event-types/components/tabs/setup/EventSetupTabWebWrapper.tsx → EventSetupTabWebWrapper
          apps/web/modules/filters/components/TeamsFilter.tsx → TeamsFilter
          apps/web/modules/formbricks/hooks/useFormbricks.ts → useFormbricks
          apps/web/modules/getting-started/[[...step]]/onboarding-view.tsx → onClick
          apps/web/modules/onboarding/components/OnboardingLayout.tsx → handleSignOut
          apps/web/modules/onboarding/hooks/useOnboardingCalendarEvents.ts → useOnboardingCalendarEvents
          apps/web/modules/onboarding/personal/_components/OnboardingLayout.tsx → handleSignOut
          apps/web/modules/settings/components/TimezoneChangeDialog.tsx → useOpenTimezoneDialog
          apps/web/modules/settings/my-account/appearance-view.tsx → AppearanceView
          apps/web/modules/settings/my-account/general-view.tsx → GeneralView
          apps/web/modules/settings/my-account/profile-view.tsx → ProfileView, onDeleteMeSuccessMutation
          apps/web/modules/settings/security/password-view.tsx → PasswordView, onSuccess
          apps/web/modules/settings/security/two-factor-auth-view.tsx → TwoFactorAuthView, onEnable
          apps/web/modules/shell/banners/useBanners.ts → useBannersInternal
          apps/web/modules/shell/Kbar.tsx → useUpcomingBookingsAction
          apps/web/modules/shell/navigation/Navigation.tsx → MobileNavigationContainer
          apps/web/modules/shell/navigation/useMobileMoreItems.ts → useMobileMoreItems
          apps/web/modules/shell/Shell.tsx → PublicShell
          apps/web/modules/shell/SideBar.tsx → SideBarContainer
          apps/web/modules/shell/TopNav.tsx → TopNavContainer
          apps/web/modules/shell/user-dropdown/ProfileDropdown.tsx → ProfileDropdown
          apps/web/modules/shell/user-dropdown/UserDropdown.tsx → onClick
          apps/web/modules/signup-view.tsx → signUp
          apps/web/modules/troubleshooter/components/LargeCalendar.tsx → LargeCalendar
          apps/web/modules/users/components/UserTable/ChangeUserRoleModal.tsx → ChangeUserRoleModal
          apps/web/modules/users/components/UserTable/DeleteMemberModal.tsx → DeleteMemberModal
          apps/web/modules/users/components/UserTable/EditSheet/EditUserForm.tsx → EditForm
          apps/web/modules/users/components/UserTable/InviteMemberModal.tsx → InviteMemberModal
          apps/web/modules/users/components/UserTable/UserListTable.tsx → UserListTableContent
          apps/web/modules/users/components/UserTable/UserTableActions.tsx → TableActions
          apps/web/modules/webhooks/views/webhook-new-view.tsx → NewWebhookView
          apps/web/pages/_app.tsx → MyApp
          apps/web/pages/api/auth/[...nextauth].ts → handler
          apps/web/server/lib/auth/login/getServerSideProps.tsx → getServerSideProps
          apps/web/server/lib/auth/signin/getServerSideProps.tsx → getServerSideProps
          packages/features/auth/lib/getLocale.ts → getLocale
          packages/features/auth/lib/getServerSession.ts → getServerSession
          packages/features/auth/lib/getSession.ts → getSession
          packages/features/auth/lib/next-auth-options.ts → (module scope), encode
          packages/features/auth/PermissionContainer.tsx → PermissionContainer
    5%  kysely  ⚠ 1 live CVE (HIGH)  (83/1834 fns run, 1751 never run, 3 file(s) never loaded) · e.g. $asScalar, $asTuple, $assertType, $call…
          packages/kysely/index.ts → (module scope)
          packages/kysely/utils/json/traverse/index.ts → traverseJSON
          packages/trpc/server/routers/viewer/bookings/get.handler.ts → (anonymous)
   31%  js-yaml  ⚠ 2 live CVEs (HIGH)  (100/320 fns run, 220 never run) · e.g. State, YAMLException, _class, binary…
          apps/web/lib/apps/[slug]/getStaticProps.ts → parseFrontmatter
   34%  nodemailer  ⚠ 6 live CVEs (HIGH)  (237/688 fns run, 451 never run, 7 file(s) never loaded) · e.g. _actionAUTHComplete, _actionAUTH_CRAM_MD5, _actionAUTH_CRAM_MD5_PASS, _actionAUTH_LOGIN_PASS…
          packages/features/auth/lib/sendVerificationRequest.ts → (module scope)
   47%  qs  ⚠ 1 live CVE (MODERATE)  (66/141 fns run, 75 never run) · e.g. RFC1738, arrayToObject, assert, assignSingleSource…
          apps/api/v2/src/main.ts → (anonymous), stdin_default
          apps/web/components/apps/hitpay/HitpayPaymentComponent.tsx → onClose
          packages/app-store/hitpay/api/callback.ts → handler
          packages/app-store/hitpay/lib/PaymentService.ts → create
          packages/app-store/zoho-bigin/api/callback.ts → handler
          packages/app-store/zoho-bigin/lib/CrmService.ts → (anonymous)
          packages/app-store/zohocrm/api/callback.ts → handler
          packages/app-store/zohocrm/lib/CrmService.ts → (anonymous)
   53%  dompurify  ⚠ 13 live CVEs (MODERATE)  (25/47 fns run, 22 never run, 1 file(s) never loaded) · e.g. DOMPurify, _sanitizeShadowDOM, addHook, apply…
          packages/lib/markdownToSafeHTMLClient.ts → markdownToSafeHTMLClient
          packages/platform/atoms/lib/markdownToSafeHTML.ts → markdownToSafeHTML
   63%  markdown-it  ⚠ 1 live CVE (MODERATE)  (140/223 fns run, 83 never run, 1 file(s) never loaded) · e.g. __find__, add, after, at…
          apps/web/lib/video/[uid]/getServerSideProps.ts → (module scope)
          packages/lib/markdownIt.ts → (module scope)
   44%  cookie  ⚠ 1 live CVE (LOW)  (4/9 fns run, 5 never run) · e.g. decode, endIndex, parse, startIndex…
          packages/trpc/server/routers/viewer/slots/reserveSlot.handler.ts → reserveSlotHandler
    0%  @urql/core  (0/297 fns run, 297 never run, 1 file(s) never loaded) · e.g. Argument, BooleanValue, Client, Directive…
          packages/app-store/salesforce/lib/graphql/SalesforceGraphQLClient.ts → constructor
    0%  @formbricks/api  (0/20 fns run, 20 never run, 1 file(s) never loaded) · e.g. __defNormalProp, __publicField, constructor, create…
          packages/lib/formbricks.ts → sendFeedbackFormbricks
          packages/trpc/server/routers/viewer/feedback/_router.ts → (anonymous)
    1%  luxon  (6/569 fns run, 563 never run, 1 file(s) never loaded) · e.g. DATETIME_FULL, DATETIME_FULL_WITH_SECONDS, DATETIME_HUGE, DATETIME_HUGE_WITH_SECONDS…
    2%  @daily-co/daily-react  (9/437 fns run, 428 never run, 1 file(s) never loaded) · e.g. $n, B, C, DailyProvider…
          apps/web/modules/videos/cal-video-premium-features.tsx → CalVideoPremiumFeatures
          apps/web/modules/videos/views/videos-single-view.tsx → JoinCall, VideoMeetingInfo
    2%  @todesktop/client-core  (6/314 fns run, 308 never run) · e.g. add, addBrowserView, addEventListenerArgsAreLegacy, addRepresentation…
          apps/web/pages/_document.tsx → (anonymous)
    2%  @urql/exchange-retry  (1/59 fns run, 58 never run, 1 file(s) never loaded) · e.g. asyncIteratorSymbol, debounce, filter, fromAsyncIterable…
          packages/app-store/salesforce/lib/graphql/SalesforceGraphQLClient.ts → constructor
    4%  @lexical/table  (13/346 fns run, 333 never run) · e.g. $createTableNodeWithDimensions, $deleteTableColumn, $getElementGridForTableNode, $getTableCellNodeFromLexicalNode…
          packages/ui/components/editor/Editor.tsx → (module scope)
    4%  @radix-ui/react-hover-card  (12/285 fns run, 273 never run, 1 file(s) never loaded) · e.g. $5cb92bef7577960e$var$dispatchUpdate, $5cb92bef7577960e$var$handleAndDispatchCustomEvent, $5cb92bef7577960e$var$useFocusOutside, $5cb92bef7577960e$var$usePointerDownOutside…
          apps/web/modules/bookings/components/AvailableTimes.tsx → SlotItem
          packages/ui/components/hover-card/index.tsx → (anonymous), (module scope)
    4%  botid  (1/28 fns run, 27 never run, 4 file(s) never loaded) · e.g. C, H, T, g…
          apps/web/instrumentation-client.ts → (module scope)
          packages/features/bot-detection/BotDetectionService.ts → checkBotDetection
    5%  @daily-co/daily-js  (75/1583 fns run, 1508 never run, 1 file(s) never loaded) · e.g. $, $e, $n, $o…
          apps/web/modules/videos/views/videos-single-view.tsx → (anonymous)
    5%  @radix-ui/react-slider  (5/111 fns run, 106 never run, 1 file(s) never loaded) · e.g. BubbleInput, CollectionProvider, Provider, clamp…
          packages/ui/components/image-uploader/Common.tsx → Slider
    6%  @lexical/list  (11/174 fns run, 163 never run) · e.g. $handleListInsertParagraph, B, C, D…
          packages/ui/components/editor/Editor.tsx → (module scope)
          packages/ui/components/editor/plugins/customEnterKeyPlugin.tsx → (anonymous)
          packages/ui/components/editor/plugins/ToolbarPlugin.tsx → (anonymous), formatBulletList, formatNumberedList
    7%  @lexical/selection  (5/68 fns run, 63 never run) · e.g. $addNodeStyle, $cloneWithProperties, $getSelectionStyleValueForProperty, $isAtNodeEnd…
          packages/ui/components/editor/plugins/ToolbarPlugin.tsx → (anonymous), getSelectedNode
    9%  ical.js  (37/416 fns run, 379 never run) · e.g. BYDAY, Binary, COUNT, Component…
          packages/app-store/ics-feedcalendar/lib/CalendarService.ts → (anonymous)
          packages/lib/CalendarService.ts → (anonymous)
    9%  @googleapis/admin  (17/197 fns run, 180 never run) · e.g. action, admin, batchChangeStatus, batchCreatePrintServers…
          packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.ts → getUsersFromGWorkspace
   12%  svix  (167/1437 fns run, 1270 never run) · e.g. HMAC, Hash, Url, _decodeChar…
          packages/app-store/alby/lib/parseInvoice.ts → parseInvoice
   12%  @lexical/rich-text  (21/170 fns run, 149 never run) · e.g. $isQuoteNode, A, B, E…
          packages/ui/components/editor/Editor.tsx → (module scope)
          packages/ui/components/editor/plugins/ToolbarPlugin.tsx → (anonymous)
   12%  @radix-ui/react-radio-group  (14/114 fns run, 100 never run, 1 file(s) never loaded) · e.g. $010c2913dbd2fe3d$export$5cae361ad82dce8b, $6ed0406888f73fc4$export$43e446d32b3d21af, $6ed0406888f73fc4$export$c7b2cbe3552a0d05, $6ed0406888f73fc4$var$setRef…
          apps/web/modules/event-types/components/tabs/advanced/DisableReschedulingController.tsx → render
          apps/web/modules/event-types/components/tabs/advanced/RequiresConfirmationController.tsx → render
          apps/web/modules/settings/components/BookerLayoutSelector.tsx → (anonymous), BookerLayoutFields
          packages/app-store/stripepayment/components/EventTypeAppSettingsInterface.tsx → EventTypeAppSettingsInterface
          packages/features/eventtypes/components/tabs/limits/EventLimitsTab.tsx → RangeLimitRadioItem, RollingLimitRadioItem, render
          packages/ui/components/radio/Radio.tsx → (module scope), Group, Indicator, Radio
          packages/ui/components/radio/RadioAreaGroup.tsx → (module scope), RadioArea, RadioAreaGroup
   12%  @lexical/utils  (7/58 fns run, 51 never run) · e.g. $dfs, $getNearestBlockElementAncestorOrThrow, $getNearestNodeOfType, $insertNodeToNearestRoot…
          packages/ui/components/editor/plugins/ToolbarPlugin.tsx → (anonymous)
   13%  @radix-ui/react-checkbox  (9/69 fns run, 60 never run, 1 file(s) never loaded) · e.g. $010c2913dbd2fe3d$export$5cae361ad82dce8b, $6ed0406888f73fc4$export$43e446d32b3d21af, $6ed0406888f73fc4$export$c7b2cbe3552a0d05, $6ed0406888f73fc4$var$setRef…
          packages/ui/components/form/checkbox/Checkbox.tsx → (anonymous), (module scope)
   13%  @formkit/auto-animate  (6/48 fns run, 42 never run) · e.g. add, animate, autoAnimate, cleanUp…
          apps/web/components/dialog/ReassignDialog.tsx → ReassignDialog
          apps/web/modules/apps/components/AllApps.tsx → AllApps
          apps/web/modules/availability/availability-view.tsx → AvailabilityList
          apps/web/modules/event-types/components/CheckedUserSelect.tsx → CheckedUserSelect
          apps/web/modules/event-types/components/EventType.tsx → EventType
          apps/web/modules/event-types/components/locations/CalVideoSettings.tsx → CalVideoSettings
          apps/web/modules/event-types/components/locations/Locations.tsx → Locations
          apps/web/modules/event-types/components/MultiplePrivateLinksController.tsx → MultiplePrivateLinksController
          apps/web/modules/event-types/components/tabs/advanced/FormBuilder.tsx → FormBuilder2, Options
          apps/web/modules/event-types/components/tabs/availability/EventAvailabilityTab.tsx → TeamAvailability
          apps/web/modules/event-types/views/event-types-listing-view.tsx → InfiniteEventTypeList
          packages/app-store/_components/AppCard.tsx → AppCard
          packages/app-store/_components/AppCategoryNavigation.tsx → AppCategoryNavigation
          packages/features/eventtypes/components/CheckedTeamSelect.tsx → CheckedTeamSelect
          packages/features/eventtypes/components/ChildrenEventTypeSelect.tsx → ChildrenEventTypeSelect
          packages/features/eventtypes/components/tabs/limits/EventLimitsTab.tsx → IntervalLimitsManager
          packages/platform/atoms/event-types/wrappers/ListEventTypesPlatformWrapper.tsx → ListEventTypesPlatformWrapper
          packages/platform/atoms/list-schedules/wrappers/ListSchedulesPlatformWrapper.tsx → ListSchedulesPlatformWrapper
          packages/ui/components/card/PanelCard.tsx → PanelCard
          packages/ui/components/form/inputs/MultiOptionInput.tsx → MultiOptionInput
          packages/ui/components/form/switch/SettingsToggle.tsx → SettingsToggle
          packages/ui/components/section/section.tsx → Root, SubSection
   14%  @tanstack/react-table  (100/707 fns run, 607 never run, 1 file(s) never loaded) · e.g. _autoResetExpanded, _autoResetPageIndex, _getPinnedRows, _getRowId…
          apps/web/app/(use-page-wrapper)/settings/(admin-layout)/admin/playground/date-range-filter/page.tsx → (module scope), ScenarioCard
          apps/web/modules/blocklist/components/BlockedEntriesTable.tsx → BlockedEntriesTable
          apps/web/modules/blocklist/components/PendingReportsTable.tsx → PendingReportsTable
          apps/web/modules/bookings/columns/filterColumns.ts → buildFilterColumns
          apps/web/modules/bookings/components/BookingCalendarContainer.tsx → BookingCalendarInner
          apps/web/modules/bookings/components/BookingListContainer.tsx → BookingListInner
          apps/web/modules/bookings/hooks/useBookingListColumns.tsx → (anonymous)
          apps/web/modules/data-table/components/DataTable.tsx → (anonymous), TableHeadLabel
          apps/web/modules/settings/outOfOffice/OutOfOfficeEntriesList.tsx → (anonymous), OutOfOfficeEntriesListContent
          apps/web/modules/users/components/UserTable/PlatformManagedUsersTable.tsx → UserListTableContent
          apps/web/modules/users/components/UserTable/UserListTable.tsx → UserListTableContent
          packages/features/schedules/components/DateOverrideList.tsx → DateOverrideList
   14%  @lexical/link  (11/81 fns run, 70 never run) · e.g. a, canBeEmpty, canInsertTextAfter, canInsertTextBefore…
          packages/ui/components/editor/Editor.tsx → (module scope)
          packages/ui/components/editor/plugins/ToolbarPlugin.tsx → (anonymous), onKeyDown
   14%  windows-iana  (4/28 fns run, 24 never run, 1 file(s) never loaded) · e.g. findIana, findIanaAliases, findWindows, r
          packages/app-store/office365calendar/lib/CalendarService.ts → getMainTimeZone
   15%  @radix-ui/react-dropdown-menu  (82/545 fns run, 463 never run, 1 file(s) never loaded) · e.g. $3db38b7d1fb3fe6a$export$b7ece24a22aeda8c, $3db38b7d1fb3fe6a$var$createFocusGuard, $5cb92bef7577960e$var$dispatchUpdate, $5cb92bef7577960e$var$handleAndDispatchCustomEvent…
          packages/ui/components/button/SplitButton.tsx → (anonymous), SplitButton2
          packages/ui/components/dropdown/Dropdown.tsx → (anonymous), (module scope), DropdownMenuLabel
   15%  async  (63/407 fns run, 344 never run, 2 file(s) never loaded) · e.g. _createTester, _filter, _withoutIndex, _withoutIndex3…
          packages/features/bookings/lib/getAllCredentialsForUsersOnEvent/refreshCredentials.ts → _refreshCredentials
   16%  @getalby/lightning-tools  (26/166 fns run, 140 never run, 1 file(s) never loaded) · e.g. $, 1, 13, 16…
          packages/app-store/alby/components/AlbyPriceComponent.tsx → (anonymous)
          packages/app-store/alby/lib/PaymentService.ts → create
   16%  @googleapis/calendar  (9/56 fns run, 47 never run) · e.g. calendar, clear, constructor, delete…
          packages/app-store/googlecalendar/api/callback.ts → getHandler
          packages/app-store/googlecalendar/lib/CalendarAuth.ts → getClient
          packages/features/auth/lib/next-auth-options.ts → jwt
   17%  @stripe/stripe-js  (3/18 fns run, 15 never run, 2 file(s) never loaded) · e.g. _typeof, findScript, initStripe, injectScript…
          packages/app-store/stripepayment/lib/client/getStripe.ts → getStripe
   18%  @radix-ui/react-tooltip  (56/312 fns run, 256 never run, 1 file(s) never loaded) · e.g. $5cb92bef7577960e$var$dispatchUpdate, $5cb92bef7577960e$var$handleAndDispatchCustomEvent, $5cb92bef7577960e$var$useFocusOutside, $5cb92bef7577960e$var$usePointerDownOutside…
          apps/web/lib/app-providers-app-dir.tsx → AppProviders
          apps/web/lib/app-providers.tsx → AppProviders
          packages/platform/atoms/cal-provider/BaseCalProvider.tsx → BaseCalProvider
          packages/ui/components/avatar/Avatar.tsx → Avatar
          packages/ui/components/tooltip/Tooltip.tsx → Tooltip
   18%  @radix-ui/react-collapsible  (11/62 fns run, 51 never run, 1 file(s) never loaded) · e.g. $409067139f391064$var$getState, $6ed0406888f73fc4$export$43e446d32b3d21af, $6ed0406888f73fc4$export$c7b2cbe3552a0d05, $6ed0406888f73fc4$var$setRef…
          apps/web/modules/bookings/views/bookings-single-view.tsx → RecurringBookings
          apps/web/modules/embed/components/Embed.tsx → EmailEmbed, EmbedTypeCodeAndPreviewDialogContent
   20%  lru-cache  (35/178 fns run, 143 never run) · e.g. abort, addEventListener, backgroundFetch, calculatedSize…
          packages/features/auth/lib/getServerSession.ts → (module scope)
   20%  react-turnstile  (6/30 fns run, 24 never run) · e.g. TURNSTILE_LOAD_FUNCTION, Turnstile, after-interactive-callback, before-interactive-callback…
          apps/web/modules/auth/components/Turnstile.tsx → TurnstileWidget
   21%  google-auth-library  (166/804 fns run, 638 never run) · e.g. DataStream, O, RETRY_CONFIG, SafeBuffer…
          packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.ts → getUsersFromGWorkspace
   22%  node-fetch  (57/262 fns run, 205 never run, 2 file(s) never loaded) · e.g. AbortError, ByteString, DOMString, Date…
          packages/features/auth/signup/utils/prefillAvatar.ts → downloadImageDataFromUrl, getImageUrlAvatarAPI
   23%  rrule  (133/573 fns run, 440 never run) · e.g. AT, At, Cache, CallbackIterResult…
          packages/app-store/googlecalendar/lib/CalendarService.ts → createEvent
          packages/app-store/salesforce/lib/CrmService.ts → (anonymous)
          packages/emails/lib/generateIcsString.ts → generateIcsString
          packages/emails/src/components/WhenInfo.tsx → getRecurringWhen
          packages/features/bookings/lib/getCalendarLinks.ts → buildGoogleCalendarLink
          packages/lib/parse-dates.ts → parseRecurringDates
   23%  i18next  (116/496 fns run, 380 never run) · e.g. 1, 10, 11, 12…
          apps/web/app/layout.tsx → getInitialProps
          apps/web/lib/app-providers.tsx → (anonymous)
          apps/web/pages/_document.tsx → render
          packages/i18n/server.ts → getTranslation
          packages/lib/hooks/useLocale.ts → useLocale
   24%  vitest-fetch-mock  (15/63 fns run, 48 never run) · e.g. abort, abortAsync, abortError, disableMocks…
   25%  lexical  (272/1100 fns run, 828 never run) · e.g. $addUpdateTag, $b, $createRangeSelection, $getTextContent…
          packages/ui/components/editor/nodes/VariableNode.ts → $createVariableNode, (module scope)
          packages/ui/components/editor/plugins/AddVariablesPlugin.tsx → (anonymous)
          packages/ui/components/editor/plugins/customEnterKeyPlugin.tsx → (anonymous)
          packages/ui/components/editor/plugins/PlainTextPlugin.tsx → (anonymous)
          packages/ui/components/editor/plugins/ToolbarPlugin.tsx → (anonymous), onClick
   25%  @radix-ui/react-label  (19/75 fns run, 56 never run) · e.g. _extends, composeRefs, createContextScope, get…
          packages/ui/components/form/switch/Switch.tsx → Switch
   26%  @base-ui/react  (365/1407 fns run, 1042 never run, 153 file(s) never loaded) · e.g. CompositeItem, CompositeList, FieldDescription, FieldItem…
          packages/coss-ui/src/components/accordion.tsx → Accordion, AccordionItem, AccordionPanel, AccordionTrigger
          packages/coss-ui/src/components/alert-dialog.tsx → (module scope), AlertDialogBackdrop, AlertDialogClose, AlertDialogDescription, AlertDialogPopup, AlertDialogTitle, AlertDialogTrigger, AlertDialogViewport
          packages/coss-ui/src/components/autocomplete.tsx → (module scope), AutocompleteClear, AutocompleteCollection, AutocompleteEmpty, AutocompleteGroup, AutocompleteGroupLabel, AutocompleteInput, AutocompleteItem…
          packages/coss-ui/src/components/avatar.tsx → Avatar, AvatarFallback, AvatarImage
          packages/coss-ui/src/components/badge.tsx → Badge
          packages/coss-ui/src/components/breadcrumb.tsx → BreadcrumbLink
          packages/coss-ui/src/components/button.tsx → Button
          packages/coss-ui/src/components/card.tsx → Card, CardAction, CardDescription, CardFooter, CardFrame, CardFrameDescription, CardFrameFooter, CardFrameHeader…
          packages/coss-ui/src/components/checkbox-group.tsx → CheckboxGroup
          packages/coss-ui/src/components/checkbox.tsx → Checkbox
          packages/coss-ui/src/components/collapsible.tsx → Collapsible, CollapsiblePanel, CollapsibleTrigger
          packages/coss-ui/src/components/combobox.tsx → (module scope), Combobox, ComboboxChip, ComboboxChipRemove, ComboboxChips, ComboboxChipsInput, ComboboxClear, ComboboxCollection…
          packages/coss-ui/src/components/command.tsx → (module scope), CommandDialogBackdrop, CommandDialogPopup, CommandDialogTrigger, CommandDialogViewport
          packages/coss-ui/src/components/dialog.tsx → (module scope), DialogBackdrop, DialogClose, DialogDescription, DialogPopup, DialogTitle, DialogTrigger, DialogViewport
          packages/coss-ui/src/components/field.tsx → (module scope), Field, FieldDescription, FieldError, FieldItem, FieldLabel
          packages/coss-ui/src/components/fieldset.tsx → Fieldset, FieldsetLegend
          packages/coss-ui/src/components/form.tsx → Form
          packages/coss-ui/src/components/group.tsx → GroupText
          packages/coss-ui/src/components/input.tsx → Input
          packages/coss-ui/src/components/label.tsx → Label
          packages/coss-ui/src/components/menu.tsx → (module scope), MenuCheckboxItem, MenuGroup, MenuGroupLabel, MenuItem, MenuPopup, MenuRadioGroup, MenuRadioItem…
          packages/coss-ui/src/components/meter.tsx → Meter, MeterIndicator, MeterLabel, MeterTrack, MeterValue
          packages/coss-ui/src/components/number-field.tsx → NumberField, NumberFieldDecrement, NumberFieldGroup, NumberFieldIncrement, NumberFieldInput, NumberFieldScrubArea
          packages/coss-ui/src/components/pagination.tsx → PaginationLink
          packages/coss-ui/src/components/popover.tsx → (module scope), PopoverClose, PopoverDescription, PopoverPopup, PopoverTitle, PopoverTrigger
          packages/coss-ui/src/components/preview-card.tsx → (module scope), PreviewCardPopup, PreviewCardTrigger
          packages/coss-ui/src/components/progress.tsx → Progress, ProgressIndicator, ProgressLabel, ProgressTrack, ProgressValue
          packages/coss-ui/src/components/radio-group.tsx → Radio, RadioGroup
          packages/coss-ui/src/components/scroll-area.tsx → ScrollArea, ScrollBar
          packages/coss-ui/src/components/select.tsx → (module scope), SelectButton, SelectGroup, SelectGroupLabel, SelectItem, SelectPopup, SelectSeparator, SelectTrigger…
          packages/coss-ui/src/components/separator.tsx → Separator
          packages/coss-ui/src/components/sheet.tsx → (module scope), SheetBackdrop, SheetClose, SheetDescription, SheetPopup, SheetTitle, SheetTrigger, SheetViewport
          packages/coss-ui/src/components/sidebar.tsx → SidebarGroupAction, SidebarGroupLabel, SidebarMenuAction, SidebarMenuButton, SidebarMenuSubButton
          packages/coss-ui/src/components/slider.tsx → (anonymous), Slider, SliderValue
          packages/coss-ui/src/components/switch.tsx → Switch
          packages/coss-ui/src/components/tabs.tsx → Tabs, TabsList, TabsPanel, TabsTab
          packages/coss-ui/src/components/textarea.tsx → Textarea, render
          packages/coss-ui/src/components/toast.tsx → (anonymous), (module scope), AnchoredToastProvider, AnchoredToasts, ToastProvider, Toasts
          packages/coss-ui/src/components/toggle-group.tsx → ToggleGroup
          packages/coss-ui/src/components/toggle.tsx → Toggle
          packages/coss-ui/src/components/toolbar.tsx → Toolbar, ToolbarButton, ToolbarGroup, ToolbarInput, ToolbarLink, ToolbarSeparator
          packages/coss-ui/src/components/tooltip.tsx → (module scope), TooltipPopup, TooltipTrigger
   26%  react-i18next  (103/397 fns run, 294 never run) · e.g. I18nextProvider, I18nextProvider$1, ReportNamespaces, Trans…
          packages/lib/hooks/useLocale.ts → useClientLocale
          packages/platform/atoms/lib/useLocale.ts → useLocale
   26%  date-fns-tz  (11/42 fns run, 31 never run, 1 file(s) never loaded) · e.g. O, X, addLeadingZeros, dayOfISOWeekYear…
          packages/features/booking-audit/lib/actions/AuditActionServiceHelper.ts → formatDateInTimeZone, formatDateTimeInTimeZone
          packages/features/schedules/components/DateOverrideList.tsx → (anonymous), timeSpan
   27%  jimp  (629/2295 fns run, 1666 never run, 1 file(s) never loaded) · e.g. AbstractDistanceCalculator, AbstractEuclidean, AbstractImageQuantizer, AbstractManhattan…
          packages/lib/server/resizeBase64Image.ts → resizeBase64Image
   27%  jose  (177/651 fns run, 474 never run, 1 file(s) never loaded) · e.g. EmbeddedJWK, add, addRecipient, addSignature…
          apps/web/server/lib/auth/login/getServerSideProps.tsx → verifyJwt
          packages/features/auth/lib/signJwt.ts → signJwt
   28%  react-day-picker  (102/358 fns run, 256 never run) · e.g. Caption, CaptionDropdowns, CaptionLabel, CaptionNavigation…
          packages/ui/components/form/date-range-picker/Calendar.tsx → Calendar
   29%  zod  (284/990 fns run, 706 never run, 6 file(s) never loaded) · e.g. BRAND, DIRTY, EMPTY_PATH, Enum…
          apps/api/v2/src/modules/stripe/utils/stripeDataSchemas.ts → (module scope)
          apps/api/v2/src/platform/event-types/event-types_2024_06_14/transformers/internal-to-api/booking-fields.ts → (module scope)
          apps/api/v2/src/platform/event-types/event-types_2024_06_14/transformers/internal/locations.ts → (module scope)
          apps/web/app/(use-page-wrapper)/(main-nav)/bookings/[status]/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/apps/[slug]/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/apps/categories/[category]/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/apps/installed/[category]/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/auth/error/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/auth/setup/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/auth/verify/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/availability/[schedule]/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/event-types/[type]/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/settings/(admin-layout)/admin/users/[id]/edit/page.tsx → (module scope)
          apps/web/app/(use-page-wrapper)/video/meeting-not-started/[uid]/page.tsx → (module scope)
          apps/web/app/api/auth/reset-password/route.ts → (module scope)
          apps/web/app/api/auth/setup/route.ts → (module scope)
          apps/web/app/api/availability/calendar/route.ts → (module scope)
          apps/web/app/api/avatar/[uuid]/route.ts → (module scope)
          apps/web/app/api/link/route.ts → (module scope)
          apps/web/app/api/logo/route.ts → (module scope)
          apps/web/app/api/social/og/image/route.tsx → (module scope), handler
          apps/web/app/api/sync/helpscout/route.ts → (module scope)
          apps/web/app/api/username/route.ts → (module scope)
          apps/web/app/api/verify-booking-token/route.ts → (module scope), postHandler
          apps/web/app/api/video/guest-session/route.ts → (module scope)
          apps/web/app/api/webhook/app-credential/route.ts → (module scope)
          apps/web/components/apps/alby/AlbyPaymentComponent.tsx → (module scope)
          apps/web/components/apps/btcpayserver/BtcpayPaymentComponent.tsx → (module scope)
          apps/web/components/apps/btcpayserver/Setup.tsx → BTCPaySetupPage
          apps/web/components/apps/exchangecalendar/Setup.tsx → (module scope)
          apps/web/components/apps/hitpay/HitpayPaymentComponent.tsx → (module scope)
          apps/web/components/apps/hitpay/Setup.tsx → HitPaySetupPage
          apps/web/components/apps/installation/ConfigureStepCard.tsx → EventTypeAppSettingsForm2
          apps/web/components/apps/paypal/PaypalPaymentComponent.tsx → (module scope)
          apps/web/components/apps/sendgrid/Setup.tsx → (module scope)
          apps/web/components/dialog/AddGuestsDialog.tsx → AddGuestsDialog
          apps/web/components/dialog/EditLocationDialog.tsx → (anonymous), EditLocationDialog
          apps/web/components/dialog/ReassignDialog.tsx → (module scope), onValueChange
          apps/web/components/getting-started/steps-views/UserSettings.tsx → UserSettings
          apps/web/components/settings/SecondaryEmailModal.tsx → SecondaryEmailModal
          apps/web/components/setup/AdminUser.tsx → (anonymous), AdminUser
          apps/web/lib/apps/[slug]/getStaticProps.ts → (module scope)
          apps/web/lib/apps/installation/[[...step]]/getServerSideProps.ts → getInstallationParams, getServerSideProps
          apps/web/lib/d/[link]/[slug]/getServerSideProps.tsx → (module scope)
          apps/web/lib/daily-webhook/schema.ts → (module scope)
          apps/web/lib/getThemeProviderProps.ts → getThemeProviderProps
          apps/web/lib/pages/auth/verify-email.ts → (module scope)
          apps/web/lib/reschedule/[uid]/getServerSideProps.ts → (module scope)
          apps/web/lib/signup/getServerSideProps.tsx → (module scope), getServerSideProps
          apps/web/modules/apps/components/AdminAppsList.tsx → (module scope)
          apps/web/modules/apps/components/AppListCardWebWrapper.tsx → (module scope)
          apps/web/modules/auth/login-view.tsx → Login
          apps/web/modules/auth/verify-view.tsx → (module scope)
          apps/web/modules/bookings/components/BookEventForm/BookingFields.tsx → (module scope)
          apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx → (module scope)
          apps/web/modules/bookings/views/bookings-single-view.tsx → (module scope)
          apps/web/modules/event-types/components/CreateEventTypeDialog.tsx → (module scope)
          apps/web/modules/event-types/components/DuplicateDialog.tsx → (module scope)
          apps/web/modules/event-types/components/EventTypeWebWrapper.tsx → EventTypeWeb
          apps/web/modules/event-types/components/tabs/advanced/FormBuilder.tsx → onChange
          apps/web/modules/event-types/views/event-types-listing-view.tsx → (module scope)
          apps/web/modules/getting-started/[[...step]]/onboarding-view.tsx → (module scope)
          apps/web/modules/onboarding/personal/settings/personal-settings-view.tsx → PersonalSettingsView
          apps/web/modules/settings/my-account/profile-view.tsx → ProfileForm
          apps/web/modules/signup-view.tsx → (module scope)
          apps/web/modules/users/components/UserTable/EditSheet/EditUserForm.tsx → (module scope)
          apps/web/modules/webhooks/components/WebhookTestDisclosure.tsx → onClick
          apps/web/server/lib/[user]/[type]/getServerSideProps.ts → (module scope)
          apps/web/server/lib/auth/verify-email-change/getServerSideProps.tsx → (module scope)
          packages/app-store/_lib/crm-schemas.ts → (module scope)
          packages/app-store/_utils/getInstalledAppPath.ts → (module scope)
          packages/app-store/_utils/oauth/parseRefreshTokenResponse.ts → (anonymous), (module scope)
          packages/app-store/_utils/oauth/universalSchema.ts → (module scope)
          packages/app-store/alby/api/webhook.ts → (module scope)
          packages/app-store/alby/lib/albyCredentialKeysSchema.ts → (module scope)
          packages/app-store/alby/lib/getAlbyKeys.ts → (module scope)
          packages/app-store/alby/zod.ts → (module scope)
          packages/app-store/basecamp3/api/projectMutation.ts → (module scope)
          packages/app-store/basecamp3/lib/getBasecampKeys.ts → (module scope)
          packages/app-store/basecamp3/zod.ts → (module scope)
          packages/app-store/btcpayserver/api/webhook.ts → (module scope)
          packages/app-store/btcpayserver/lib/btcpayCredentialKeysSchema.ts → (module scope)
          packages/app-store/btcpayserver/zod.ts → (module scope)
          packages/app-store/closecom/lib/CrmService.ts → (module scope)
          packages/app-store/closecom/zod.ts → (module scope)
          packages/app-store/dailyvideo/lib/getDailyAppKeys.ts → (module scope)
          packages/app-store/dailyvideo/lib/types.ts → (module scope)
          packages/app-store/dailyvideo/lib/VideoApiAdapter.ts → (anonymous)
          packages/app-store/dailyvideo/zod.ts → (module scope)
          packages/app-store/databuddy/zod.ts → (module scope)
          packages/app-store/dub/lib/utils.ts → (module scope)
          packages/app-store/dub/zod.ts → (module scope)
          packages/app-store/eventTypeAppCardZod.ts → (module scope)
          packages/app-store/exchange2013calendar/api/add.ts → (module scope)
          packages/app-store/exchange2016calendar/api/add.ts → (module scope)
          packages/app-store/exchangecalendar/api/_postAdd.ts → (module scope)
          packages/app-store/fathom/zod.ts → (module scope)
          packages/app-store/feishucalendar/api/add.ts → (module scope)
          packages/app-store/feishucalendar/api/callback.ts → (module scope)
          packages/app-store/feishucalendar/api/events.ts → (module scope)
          packages/app-store/feishucalendar/lib/AppAccessToken.ts → (module scope)
          packages/app-store/feishucalendar/zod.ts → (module scope)
          packages/app-store/ga4/zod.ts → (module scope)
          packages/app-store/giphy/api/get.ts → (anonymous), (module scope)
          packages/app-store/giphy/api/search.ts → (anonymous), (module scope)
          packages/app-store/giphy/zod.ts → (module scope)
          packages/app-store/googlecalendar/lib/getGoogleAppKeys.ts → (module scope)
          packages/app-store/googlecalendar/lib/googleCredentialSchema.ts → (module scope)
          packages/app-store/googlecalendar/zod.ts → (module scope)
          packages/app-store/googlevideo/zod.ts → (module scope)
          packages/app-store/gtm/zod.ts → (module scope)
          packages/app-store/hitpay/api/callback.ts → (module scope)
          packages/app-store/hitpay/lib/hitpayCredentialKeysSchema.ts → (module scope)
          packages/app-store/hitpay/zod.ts → (module scope)
          packages/app-store/hubspot/zod.ts → (module scope)
          packages/app-store/huddle01video/utils/storage.ts → (module scope)
          packages/app-store/insihts/zod.ts → (module scope)
          packages/app-store/intercom/zod.ts → (module scope)
          packages/app-store/jelly/api/add.ts → (module scope)
          packages/app-store/jelly/zod.ts → (module scope)
          packages/app-store/jitsivideo/zod.ts → (module scope)
          packages/app-store/larkcalendar/api/add.ts → (module scope)
          packages/app-store/larkcalendar/api/callback.ts → (module scope)
          packages/app-store/larkcalendar/api/events.ts → (module scope)
          packages/app-store/larkcalendar/lib/AppAccessToken.ts → (module scope)
          packages/app-store/larkcalendar/zod.ts → (module scope)
          packages/app-store/locations.ts → (anonymous), getTranslatedLocation, locationsResolver
          packages/app-store/lyra/zod.ts → (module scope)
          packages/app-store/make/api/subscriptions/deleteSubscription.ts → (module scope)
          packages/app-store/make/zod.ts → (module scope)
          packages/app-store/matomo/zod.ts → (module scope)
          packages/app-store/metapixel/zod.ts → (module scope)
          packages/app-store/mock-payment-app/zod.ts → (module scope)
          packages/app-store/nextcloudtalk/lib/VideoApiAdapter.ts → (module scope)
          packages/app-store/nextcloudtalk/zod.ts → (module scope)
          packages/app-store/office365calendar/lib/getOfficeAppKeys.ts → (module scope)
          packages/app-store/office365calendar/zod.ts → (module scope)
          packages/app-store/office365video/lib/VideoApiAdapter.ts → (module scope)
          packages/app-store/office365video/zod.ts → (module scope)
          packages/app-store/paypal/api/capture.ts → (module scope)
          packages/app-store/paypal/api/webhook.ts → (module scope)
          packages/app-store/paypal/lib/PaymentService.ts → (module scope)
          packages/app-store/paypal/lib/Paypal.ts → (module scope)
          packages/app-store/paypal/lib/updateAppCredentials.validator.ts → (module scope)
          packages/app-store/paypal/zod.ts → (module scope)
          packages/app-store/pipedrive-crm/lib/getPipedriveAppKeys.ts → (module scope)
          packages/app-store/pipedrive-crm/zod.ts → (module scope)
          packages/app-store/plausible/zod.ts → (module scope)
          packages/app-store/posthog/zod.ts → (module scope)
          packages/app-store/qr_code/zod.ts → (module scope)
          packages/app-store/salesforce/lib/CrmService.ts → (module scope)
          packages/app-store/salesforce/lib/getSalesforceAppKeys.ts → (module scope)
          packages/app-store/salesforce/zod.ts → (module scope)
          packages/app-store/sendgrid/lib/CalendarService.ts → (module scope)
          packages/app-store/shimmervideo/lib/getShimmerAppKeys.ts → (module scope)
          packages/app-store/shimmervideo/lib/VideoApiAdapter.ts → (module scope)
          packages/app-store/shimmervideo/zod.ts → (module scope)
          packages/app-store/stripepayment/api/add.ts → handler
          packages/app-store/stripepayment/api/paymentCallback.ts → (module scope)
          packages/app-store/stripepayment/lib/PaymentService.ts → (module scope)
          packages/app-store/stripepayment/lib/server.ts → (module scope)
          packages/app-store/stripepayment/pages/setup/_getServerSideProps.ts → getServerSideProps
          packages/app-store/stripepayment/zod.ts → (module scope)
          packages/app-store/tandemvideo/zod.ts → (module scope)
          packages/app-store/templates/booking-pages-tag/zod.ts → (module scope)
          packages/app-store/templates/event-type-app-card/zod.ts → (module scope)
          packages/app-store/twipla/zod.ts → (module scope)
          packages/app-store/umami/zod.ts → (module scope)
          packages/app-store/vital/api/save.ts → (anonymous)
          packages/app-store/vital/zod.ts → (module scope)
          packages/app-store/webex/lib/getWebexAppKeys.ts → (module scope)
          packages/app-store/webex/lib/VideoApiAdapter.ts → (module scope)
          packages/app-store/webex/zod.ts → (module scope)
          packages/app-store/wipemycalother/api/wipe.ts → (anonymous), (module scope)
          packages/app-store/wordpress/zod.ts → (module scope)
          packages/app-store/zapier/api/subscriptions/deleteSubscription.ts → (module scope)
          packages/app-store/zapier/zod.ts → (module scope)
          packages/app-store/zod-utils.ts → (module scope)
          packages/app-store/zoho-bigin/zod.ts → (module scope)
          packages/app-store/zohocalendar/zod.ts → (module scope)
          packages/app-store/zohocrm/zod.ts → (module scope)
          packages/app-store/zoomvideo/lib/getZoomAppKeys.ts → (module scope)
          packages/app-store/zoomvideo/lib/VideoApiAdapter.ts → (module scope)
          packages/app-store/zoomvideo/zod.ts → (module scope)
          packages/emails/templates/_base-email.ts → sendEmail
          packages/features/apps/components/AppSetDefaultLinkDialog.tsx → AppSetDefaultLinkDialog
          packages/features/auth/signup/username.ts → (module scope)
          packages/features/availability/lib/getUserAvailability.ts → (module scope)
          packages/features/booking-audit/lib/actions/AcceptedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/AttendeeAddedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/AttendeeRemovedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/AuditActionServiceHelper.ts → getVersion
          packages/features/booking-audit/lib/actions/CancelledAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/CreatedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/LocationChangedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/NoShowUpdatedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/ReassignmentAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/RejectedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/RescheduledAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/RescheduleRequestedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/SeatBookedAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/actions/SeatRescheduledAuditActionService.ts → (module scope)
          packages/features/booking-audit/lib/common/changeSchemas.ts → (module scope)
          packages/features/booking-audit/lib/dto/types.ts → (module scope)
          packages/features/booking-audit/lib/types/actionSource.ts → (module scope)
          packages/features/booking-audit/lib/types/bookingAuditTask.ts → (module scope)
          packages/features/bookings/Booker/hooks/useBookingForm.ts → useBookingForm
          packages/features/bookings/lib/bookingCreateBodySchema.ts → (module scope)
          packages/features/bookings/lib/dto/schema.ts → (module scope)
          packages/features/bookings/lib/getBookingDataSchema.ts → getBookingDataSchema
          packages/features/bookings/lib/getBookingDataSchemaForApi.ts → getBookingDataSchemaForApi
          packages/features/bookings/lib/getBookingResponsesSchema.ts → (anonymous), (module scope), getBookingResponsesSchema, getBookingResponsesSchemaWithOptionalChecks, preprocess, superRefineField
          packages/features/bookings/lib/handleNewBooking/handleCustomInputs.ts → validateBooleanInput, validatePhoneInput, validateStringInput
          packages/features/bookings/lib/tasker/trigger/notifications/schema.ts → (module scope)
          packages/features/bookings/lib/useFilterQuery.tsx → (module scope)
          packages/features/calendars/lib/tasker/trigger/schema.ts → (module scope)
          packages/features/credentials/handleDeleteCredential.ts → (module scope)
          packages/features/data-table/lib/types.ts → (module scope)
          packages/features/data-table/repositories/filterSegment.type.ts → (module scope)
          packages/features/eventtypes/components/BulkEditDefaultForEventsModal.tsx → (module scope)
          packages/features/eventtypes/lib/eventNaming.ts → (module scope)
          packages/features/eventtypes/lib/schemas.ts → (module scope)
          packages/features/filters/lib/getTeamsFiltersFromQuery.ts → (module scope)
          packages/features/flags/repositories/schemas.ts → (module scope)
          packages/features/form-builder/schema.ts → (anonymous), (module scope), nonEmptyString, preprocess, superRefine
          packages/features/handleMarkNoShow.ts → (module scope)
          packages/features/schedules/services/ScheduleService.ts → (module scope)
          packages/features/tasker/tasks/analytics/schema.ts → (module scope)
          packages/features/tasker/tasks/crm/schema.ts → (module scope)
          packages/features/tasker/tasks/sendAwaitingPaymentEmail.ts → (module scope)
          packages/features/tasker/tasks/sendWebook.ts → (module scope)
          packages/features/tasker/tasks/translateEventTypeData.ts → (module scope)
          packages/features/tasker/tasks/triggerNoShow/schema.ts → (module scope)
          packages/features/webhooks/lib/types/webhookTask.ts → (module scope)
          packages/lib/apps/getInstallCountPerApp.ts → computeInstallCountsFromDB
          packages/lib/bookings/SystemField.ts → (module scope)
          packages/lib/dayjs/index.ts → (module scope)
          packages/lib/dayjs/timeZone.schema.ts → (module scope)
          packages/lib/dbReadResponseSchema.ts → (module scope)
          packages/lib/domainManager/deploymentServices/cloudflare.ts → (module scope), getDnsRecordToDelete
          packages/lib/domainManager/deploymentServices/vercel.ts → (module scope)
          packages/lib/dto/FeatureDto.ts → (module scope)
          packages/lib/dto/TeamFeaturesDto.ts → (module scope)
          packages/lib/dto/UserFeaturesDto.ts → (module scope)
          packages/lib/emailSchema.ts → (module scope)
          packages/lib/getAvatarUrl.ts → getAbsoluteAvatarUrl
          packages/lib/getIP.ts → (module scope)
          packages/lib/hooks/useTypedQuery.ts → (anonymous), (module scope)
          packages/lib/intervalLimits/intervalLimitSchema.ts → (module scope)
          packages/lib/server/getServerErrorFromUnknown.ts → isZodError
          packages/lib/server/serviceAccountKey.ts → (module scope)
          packages/lib/stripe-error.ts → (module scope)
          packages/lib/tracking/server.ts → (module scope)
          packages/lib/zod/eventType.ts → (module scope)
          packages/lib/zod/ssrfSafeUrl.ts → (module scope)
          packages/platform/atoms/event-types/hooks/useEventTypeForm.ts → (anonymous), useEventTypeForm
          packages/platform/types/me.ts → (module scope)
          packages/platform/types/me/outputs/me.ts → (module scope)
          packages/prisma/zod-utils.ts → (anonymous), (module scope), denullish, denullishShape, getStringAsNumberRequiredSchema, optionToValueSchema
          packages/prisma/zod/inputTypeSchemas/AccessCodeScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AccessScopeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AccessTokenScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AccountScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AgentScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/ApiKeyScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AppCategoriesSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AppScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AssignmentReasonEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AssignmentReasonScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AttendeeScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AttributeOptionScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AttributeScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AttributeSyncFieldMappingScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AttributeSyncRuleScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AttributeToUserScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AttributeTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AuditActorScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AuditActorTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AvailabilityScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/AvatarScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BillingModeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BillingPeriodSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingAuditActionSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingAuditScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingAuditSourceSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingAuditTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingDenormalizedScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingInternalNoteScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingReferenceScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingReportReasonSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingReportScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingReportStatusSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingSeatScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingStatusSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingTimeStatusDenormalizedScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/BookingTimeStatusScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CalAiPhoneNumberScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CalendarCacheEventScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CalendarCacheEventStatusSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CalendarCacheScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CalVideoSettingsScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CancellationReasonRequirementSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CreationSourceSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CredentialScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CreditBalanceScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CreditExpenseLogScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CreditPurchaseLogScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CreditTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/CreditUsageTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/DelegationCredentialScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/DeploymentScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/DestinationCalendarScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/DSyncDataScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/DSyncTeamGroupMappingScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/EventTypeAutoTranslatedFieldSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/EventTypeCustomInputScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/EventTypeCustomInputTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/EventTypeScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/EventTypeTranslationScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/FeatureScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/FeatureTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/FeedbackScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/FilterSegmentScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/FilterSegmentScopeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/HashedLinkScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/HolidayCacheScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/HostGroupScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/HostLocationScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/HostScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/IdentityProviderSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/InputJsonValueSchema.ts → (anonymous), (module scope)
          packages/prisma/zod/inputTypeSchemas/InstantMeetingTokenScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/IntegrationAttributeSyncScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/InternalNotePresetScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/JsonNullValueFilterSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/JsonNullValueInputSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/JsonValueSchema.ts → (anonymous), (module scope)
          packages/prisma/zod/inputTypeSchemas/ManagedOrganizationScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/MembershipRoleSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/MembershipScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/MonthlyProrationScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/NotificationsSubscriptionsScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/NullableJsonNullValueInputSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/NullsOrderSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/OAuthClientScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/OAuthClientStatusSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/OAuthClientTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/OrganizationBillingScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/OrganizationOnboardingScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/OrganizationSettingsScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/OutOfOfficeEntryScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/OutOfOfficeReasonScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/PaymentOptionSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/PaymentScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/PeriodTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/PhoneNumberSubscriptionStatusSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/PlatformAuthorizationTokenScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/PlatformBillingScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/PlatformOAuthClientScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/ProfileScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/ProrationStatusSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/QueryModeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/RateLimitScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/RedirectTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/RefreshTokenScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/ReminderMailScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/ReminderTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/ResetPasswordRequestScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/RolePermissionScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/RoleScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/RoleTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/RRResetIntervalSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/RRTimestampBasisSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/ScheduleScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SchedulingTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SeatChangeLogScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SeatChangeTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SecondaryEmailScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SelectedCalendarScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SelectedSlotsScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SessionScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SMSLockStateSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SortOrderSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/SystemReportStatusSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TaskScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TeamBillingScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TeamFeaturesScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TeamScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TempOrgRedirectScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TimeUnitSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TrackingScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TransactionIsolationLevelSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/TravelScheduleScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/UserFeaturesScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/UserFilterSegmentPreferenceScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/UserHolidaySettingsScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/UserPasswordScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/UserPermissionRoleSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/UserScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/VerificationTokenScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/VerifiedEmailScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/VerifiedNumberScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/VideoCallGuestScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WatchlistActionSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WatchlistAuditScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WatchlistEventAuditScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WatchlistScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WatchlistSourceSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WatchlistTypeSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WebhookScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WebhookScheduledTriggersScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WebhookTriggerEventsSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WorkspacePlatformScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WrongAssignmentReportScalarFieldEnumSchema.ts → (module scope)
          packages/prisma/zod/inputTypeSchemas/WrongAssignmentReportStatusSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AccessCodeSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AccessTokenSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AccountSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AgentSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/ApiKeySchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AppSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AssignmentReasonSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AttendeeSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AttributeOptionSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AttributeSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AttributeSyncFieldMappingSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AttributeSyncRuleSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AttributeToUserSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AuditActorSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AvailabilitySchema.ts → (module scope)
          packages/prisma/zod/modelSchema/AvatarSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingAuditSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingDenormalizedSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingInternalNoteSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingReferenceSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingReportSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingSeatSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingTimeStatusDenormalizedSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/BookingTimeStatusSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/CalAiPhoneNumberSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/CalendarCacheEventSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/CalendarCacheSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/CalVideoSettingsSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/CredentialSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/CreditBalanceSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/CreditExpenseLogSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/CreditPurchaseLogSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/DelegationCredentialSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/DeploymentSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/DestinationCalendarSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/DSyncDataSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/DSyncTeamGroupMappingSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/EventTypeCustomInputSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/EventTypeSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/EventTypeTranslationSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/FeatureSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/FeedbackSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/FilterSegmentSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/HashedLinkSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/HolidayCacheSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/HostGroupSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/HostLocationSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/HostSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/InstantMeetingTokenSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/IntegrationAttributeSyncSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/InternalNotePresetSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/ManagedOrganizationSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/MembershipSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/MonthlyProrationSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/NotificationsSubscriptionsSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/OAuthClientSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/OrganizationBillingSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/OrganizationOnboardingSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/OrganizationSettingsSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/OutOfOfficeEntrySchema.ts → (module scope)
          packages/prisma/zod/modelSchema/OutOfOfficeReasonSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/PaymentSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/PlatformAuthorizationTokenSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/PlatformBillingSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/PlatformOAuthClientSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/ProfileSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/RateLimitSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/RefreshTokenSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/ReminderMailSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/ResetPasswordRequestSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/RolePermissionSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/RoleSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/ScheduleSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/SeatChangeLogSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/SecondaryEmailSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/SelectedCalendarSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/SelectedSlotsSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/SessionSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/TaskSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/TeamBillingSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/TeamFeaturesSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/TeamSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/TempOrgRedirectSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/TrackingSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/TravelScheduleSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/UserFeaturesSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/UserFilterSegmentPreferenceSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/UserHolidaySettingsSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/UserPasswordSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/UserSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/VerificationTokenSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/VerifiedEmailSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/VerifiedNumberSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/VideoCallGuestSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/WatchlistAuditSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/WatchlistEventAuditSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/WatchlistSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/WebhookScheduledTriggersSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/WebhookSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/WorkspacePlatformSchema.ts → (module scope)
          packages/prisma/zod/modelSchema/WrongAssignmentReportSchema.ts → (module scope)
          packages/trpc/server/errorFormatter.ts → errorFormatter
          packages/trpc/server/procedures/pbacProcedures.ts → createTeamPbacProcedure
          packages/trpc/server/routers/features/_router.ts → (module scope)
          packages/trpc/server/routers/loggedInViewer/addNotificationsSubscription.handler.ts → (module scope)
          packages/trpc/server/routers/loggedInViewer/addNotificationsSubscription.schema.ts → (module scope)
          packages/trpc/server/routers/loggedInViewer/addSecondaryEmail.schema.ts → (module scope)
          packages/trpc/server/routers/loggedInViewer/connectAndJoin.schema.ts → (module scope)
          packages/trpc/server/routers/loggedInViewer/eventTypeOrder.schema.ts → (module scope)
          packages/trpc/server/routers/loggedInViewer/removeNotificationsSubscription.schema.ts → (module scope)
          packages/trpc/server/routers/loggedInViewer/teamsAndUserProfilesQuery.schema.ts → (module scope)
          packages/trpc/server/routers/publicViewer/checkIfUserEmailVerificationRequired.schema.ts → (module scope)
          packages/trpc/server/routers/publicViewer/event.schema.ts → (module scope)
          packages/trpc/server/routers/publicViewer/markHostAsNoShow.schema.ts → (module scope)
          packages/trpc/server/routers/publicViewer/submitRating.schema.ts → (module scope)
          packages/trpc/server/routers/publicViewer/timezones/cityTimezones.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/assignFeatureToTeam.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/createCoupon.handler.ts → createCoupon
          packages/trpc/server/routers/viewer/admin/createCoupon.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/createSelfHostedLicenseKey.handler.ts → createSelfHostedInstance
          packages/trpc/server/routers/viewer/admin/createSelfHostedLicenseKey.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/getTeamsForFeature.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/listPaginated.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/lockUserAccount.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/removeTwoFactor.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/sendPasswordReset.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/setSMSLockState.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/toggleFeatureFlag.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/unassignFeatureFromTeam.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/addToWatchlist.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/bulkDelete.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/bulkDismiss.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/create.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/delete.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/dismissReport.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/getDetails.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/list.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/admin/watchlist/listReports.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apiKeys/create.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apiKeys/delete.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apiKeys/edit.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apiKeys/findKeyOfType.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/appById.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/appCredentialsByType.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/checkGlobalKeys.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/integrations.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/listLocal.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/locationOptions.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/queryForDependencies.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/saveKeys.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/setDefaultConferencingApp.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/toggle.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/updateAppCredentials.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/apps/updateUserDefaultConferencingApp.handler.ts → updateUserDefaultConferencingAppHandler
          packages/trpc/server/routers/viewer/apps/updateUserDefaultConferencingApp.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/auth/changePassword.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/auth/resendVerifyEmail.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/auth/sendVerifyEmailCode.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/auth/verifyPassword.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/calendarOverlay.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/schedule/bulkUpdateDefaultAvailability.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/schedule/create.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/schedule/delete.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/schedule/duplicate.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/schedule/get.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/schedule/getAllSchedulesByUserId.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/schedule/getScheduleByEventTypeSlug.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/schedule/getScheduleByUserId.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/team/listTeamAvailability.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/availability/user.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/addGuests.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/editLocation.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/find.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/get.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/getBookingAttendees.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/getBookingDetails.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/getBookingHistory.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/getWrongAssignmentReports.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/hasWrongAssignmentReport.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/reportBooking.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/reportWrongAssignment.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/requestReschedule.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/types.ts → (module scope)
          packages/trpc/server/routers/viewer/bookings/updateWrongAssignmentReportStatus.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/calendars/connectedCalendars.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/calendars/setDestinationCalendar.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/calendars/setDestinationReminder.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/calVideo/getCalVideoRecordings.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/calVideo/getDownloadLinkOfCalVideoRecordings.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/calVideo/getMeetingInformation.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/credentials/deleteCredential.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/deploymentSetup/update.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/deploymentSetup/validateLicense.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/_router.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/bulkUpdateToDefaultLocation.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/delete.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/exportHostsForWeights.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/get.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/getActiveOnOptions.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/getByViewer.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/getChildrenForAssignment.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/getHashedLink.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/getHashedLinks.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/getHostsForAssignment.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/getHostsForAvailability.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/getHostsWithLocationOptions.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/massApplyHostLocation.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/searchTeamMembers.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/types.ts → (module scope)
          packages/trpc/server/routers/viewer/eventTypes/util.ts → (module scope), createEventPbacProcedure
          packages/trpc/server/routers/viewer/feedback/_router.ts → (module scope)
          packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.ts → (module scope)
          packages/trpc/server/routers/viewer/holidays/checkConflicts.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/holidays/getUserSettings.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/holidays/toggleHoliday.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/holidays/updateSettings.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/i18n/i18n.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/me/deleteMe.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/me/get.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/me/updateProfile.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/oAuth/createClient.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/oAuth/deleteClient.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/oAuth/generateAuthCode.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/oAuth/getClientForAuthorization.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/oAuth/listClients.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/oAuth/submitClientForReview.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/oAuth/updateClient.schema.ts → (anonymous), (module scope)
          packages/trpc/server/routers/viewer/ooo/outOfOfficeCreateOrUpdate.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/ooo/outOfOfficeEntriesList.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/ooo/outOfOfficeEntryDelete.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/payments/type.ts → (module scope)
          packages/trpc/server/routers/viewer/slots/isAvailable.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/slots/types.ts → (module scope)
          packages/trpc/server/routers/viewer/users/_router.ts → (module scope)
          packages/trpc/server/routers/viewer/webhook/create.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/webhook/delete.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/webhook/edit.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/webhook/list.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/webhook/testTrigger.schema.ts → (module scope)
          packages/trpc/server/routers/viewer/webhook/types.ts → (module scope)
          packages/types/AppMetaSchema.ts → (module scope)
          packages/ui/components/file-uploader/FileUploader.tsx → (module scope)
   29%  @prisma/generator-helper  (61/214 fns run, 153 never run) · e.g. $, GeneratorError, GeneratorProcess, LineStream…
          packages/prisma/enum-generator.ts → (module scope)
   30%  glob  (308/1013 fns run, 705 never run) · e.g. ABORT, BUFFERPUSH, BUFFERSHIFT, EMITDATA…
          apps/web/pagesAndRewritePaths.ts → (module scope)
   32%  framer-motion  (350/1080 fns run, 730 never run, 1 file(s) never loaded) · e.g. AnimateSharedLayout, LayoutGroup, MeasureLayout, MotionConfig…
          apps/web/modules/auth/verify-view.tsx → PaymentSuccess
          apps/web/modules/bookings/components/AvailableTimes.tsx → SlotItem
          apps/web/modules/bookings/components/Booker.tsx → Booker, BookerComponent
          apps/web/modules/bookings/components/EventMeta.tsx → EventMeta
          apps/web/modules/onboarding/components/onboarding-browser-view.tsx → OnboardingBrowserView
          apps/web/modules/onboarding/components/onboarding-calendar-browser-view.tsx → OnboardingCalendarBrowserView
          apps/web/modules/onboarding/components/onboarding-invite-browser-view.tsx → OnboardingInviteBrowserView
          apps/web/modules/onboarding/components/onboarding-migrate-members-browser-view.tsx → OnboardingMigrateMembersBrowserView
          apps/web/modules/onboarding/components/onboarding-organization-browser-view.tsx → OnboardingOrganizationBrowserView
          apps/web/modules/onboarding/components/OnboardingCard.tsx → OnboardingCard
          apps/web/modules/onboarding/components/plan-icon.tsx → PlanIcon, renderSmallUserIcon
          apps/web/modules/onboarding/getting-started/onboarding-view.tsx → OnboardingView
          packages/features/bookings/Booker/config.ts → (anonymous), useBookerResizeAnimation
          packages/features/bookings/Booker/framer-features.tsx → (module scope)
          packages/features/bookings/components/Section.tsx → BookerSection2
   32%  node-html-parser  (198/614 fns run, 416 never run) · e.g. CDATA2, Comment2, CommentNode2, DataNode2…
          packages/testing/src/lib/bookingScenario/expects.ts → toHaveEmail
   32%  googleapis-common  (89/275 fns run, 186 never run) · e.g. O, _defaultAdapter, _getClient, _request…
          packages/app-store/googlecalendar/api/add.ts → getHandler
          packages/app-store/googlecalendar/api/callback.ts → getHandler
          packages/app-store/googlecalendar/lib/CalendarAuth.ts → (module scope), getJwtClientSingleton
          packages/features/auth/lib/next-auth-options.ts → jwt
   33%  city-timezones  (3/9 fns run, 6 never run) · e.g. findFromCityStateProvince, findPartialMatch, lookupViaCity
          packages/features/cityTimezones/cityTimezonesHandler.ts → cityTimezonesHandler
   35%  nuqs  (71/202 fns run, 131 never run) · e.g. abort, applyPendingUpdates, compareDates, compose…
          apps/web/lib/app-providers-app-dir.tsx → AppProviders
          apps/web/lib/app-providers.tsx → AppProviders
          apps/web/modules/bookings/hooks/useActiveSegmentFromUrl.ts → useActiveSegmentFromUrl
          apps/web/modules/bookings/hooks/useBookingsView.ts → (module scope), useBookingsView
          apps/web/modules/bookings/hooks/useCurrentWeekStart.ts → (module scope), useCurrentWeekStart
          apps/web/modules/bookings/hooks/useSelectedBookingId.ts → useSelectedBookingId
          apps/web/modules/bookings/hooks/useSelectedBookingUid.ts → useSelectedBookingUid
          apps/web/modules/data-table/contexts/DataTableStateContext.tsx → DataTableStateProvider
          apps/web/modules/shell/hooks/useWelcomeToCalcomModal.ts → useWelcomeToCalcomModal
          apps/web/modules/users/components/UserTable/BulkActions/DynamicLink.tsx → DynamicLink
          apps/web/modules/users/components/UserTable/UserListTable.tsx → UserListTableContent
          packages/features/data-table/lib/parsers.ts → (module scope), parse
          packages/features/data-table/lib/serializers.ts → (module scope)
          packages/ui/components/form/wizard/useWizardState.ts → createStepParser, useWizardState
   35%  @prisma/adapter-pg  (40/114 fns run, 74 never run, 1 file(s) never loaded) · e.g. $, bgBlack, bgBlue, bgCyan…
          packages/prisma/index.ts → (module scope), customPrisma
   35%  @trpc/next  (6/17 fns run, 11 never run, 1 file(s) never loaded) · e.g. WithTRPC, getAppTreeProps, getInitialProps, shouldDehydrateQuery…
          packages/trpc/react/trpc.ts → (module scope)
   36%  libphonenumber-js  (519/1426 fns run, 907 never run, 9 file(s) never loaded) · e.g. AsYouType, AsYouTypeFormatter, AsYouTypeParser, AsYouTypeState…
          apps/web/components/dialog/EditLocationDialog.tsx → (anonymous)
          apps/web/components/phone-input/PhoneInput.tsx → refactorMeWithoutEffect
          apps/web/modules/event-types/components/CreateEventTypeDialog.tsx → (anonymous)
          packages/app-store/locations.ts → (anonymous)
          packages/features/bookings/lib/getBookingResponsesSchema.ts → (anonymous)
          packages/features/bookings/lib/handleNewBooking/handleCustomInputs.ts → (anonymous)
          packages/lib/formatPhoneNumber.ts → formatPhoneNumber
   36%  react-hook-form  (154/431 fns run, 277 never run) · e.g. $, Ae, B, Be…
          apps/web/components/apps/applecalendar/Setup.tsx → AppleCalendarSetup
          apps/web/components/apps/btcpayserver/Setup.tsx → BTCPaySetupPage
          apps/web/components/apps/caldavcalendar/Setup.tsx → CalDavCalendarSetup
          apps/web/components/apps/exchange2013calendar/Setup.tsx → Exchange2013CalendarSetup
          apps/web/components/apps/exchange2016calendar/Setup.tsx → Exchange2016CalendarSetup
          apps/web/components/apps/exchangecalendar/Setup.tsx → ExchangeSetup
          apps/web/components/apps/hitpay/Setup.tsx → HitPaySetupPage
          apps/web/components/apps/ics-feedcalendar/Setup.tsx → ICSFeedSetup
          apps/web/components/apps/installation/ConfigureStepCard.tsx → ConfigureStepCardContent, EventTypeAppSettingsForm2, EventTypeGroup
          apps/web/components/apps/installation/EventTypeConferencingAppSettings.tsx → LocationsWrapper
          apps/web/components/apps/installation/EventTypesStepCard.tsx → EventTypeGroup, EventTypesStepCard
          apps/web/components/apps/sendgrid/Setup.tsx → SendgridSetup
          apps/web/components/auth/BackupCode.tsx → TwoFactor
          apps/web/components/auth/TwoFactor.tsx → TwoFactor
          apps/web/components/booking/BookingListItem.tsx → (anonymous), GroupedAttendees
          apps/web/components/dialog/EditLocationDialog.tsx → EditLocationDialog, LocationInput, success
          apps/web/components/dialog/ReassignDialog.tsx → ReassignDialog
          apps/web/components/dialog/ReportBookingDialog.tsx → ReportBookingDialog
          apps/web/components/dialog/WrongAssignmentDialog.tsx → AdditionalNotesSection, AssigneeSection, WrongAssignmentDialog
          apps/web/components/getting-started/steps-views/SetupAvailability.tsx → SetupAvailability
          apps/web/components/getting-started/steps-views/UserProfile.tsx → UserProfile
          apps/web/components/getting-started/steps-views/UserSettings.tsx → UserSettings
          apps/web/components/security/DisableTwoFactorModal.tsx → DisableTwoFactorAuthModal
          apps/web/components/security/EnableTwoFactorModal.tsx → EnableTwoFactorModal
          apps/web/components/settings/DisableTwoFactorModal.tsx → DisableTwoFactorAuthModal
          apps/web/components/settings/EnableTwoFactorModal.tsx → EnableTwoFactorModal
          apps/web/components/settings/SecondaryEmailModal.tsx → SecondaryEmailModal
          apps/web/components/setup/AdminUser.tsx → AdminUser
          apps/web/components/ui/UsernameAvailability/index.tsx → UsernameAvailabilityField
          apps/web/modules/api-keys/api-keys/components/ApiKeyDialogForm.tsx → ApiKeyDialogForm
          apps/web/modules/apps/components/AdminAppsList.tsx → (anonymous), EditKeysModal
          apps/web/modules/apps/installation/[[...step]]/step-view.tsx → OnboardingPage
          apps/web/modules/auth/forgot-password/[id]/forgot-password-single-view.tsx → Page
          apps/web/modules/auth/login-view.tsx → Login
          apps/web/modules/blocklist/components/BookingReportDetailsModal.tsx → BookingReportDetailsModal
          apps/web/modules/blocklist/components/CreateBlocklistEntryModal.tsx → CreateBlocklistEntryModal
          apps/web/modules/bookings/components/BookEventForm/BookingFields.tsx → BookingFields
          apps/web/modules/data-table/components/filters/NumberFilterOptions.tsx → NumberFilterOptions
          apps/web/modules/data-table/components/filters/TextFilterOptions.tsx → TextFilterOptions
          apps/web/modules/data-table/components/segment/DuplicateSegmentDialog.tsx → DuplicateSegmentDialog
          apps/web/modules/data-table/components/segment/RenameSegmentDialog.tsx → RenameSegmentDialog
          apps/web/modules/data-table/components/segment/SaveFilterSegmentButton.tsx → SaveFilterSegmentButton
          apps/web/modules/event-types/components/DuplicateDialog.tsx → DuplicateDialog
          apps/web/modules/event-types/components/locations/CalVideoSettings.tsx → CalVideoSettings
          apps/web/modules/event-types/components/locations/DefaultLocationSettings.tsx → DefaultLocationSettings
          apps/web/modules/event-types/components/locations/HostLocations.tsx → HostLocations
          apps/web/modules/event-types/components/locations/LocationInput.tsx → LocationInput
          apps/web/modules/event-types/components/locations/Locations.tsx → Locations
          apps/web/modules/event-types/components/MultiplePrivateLinksController.tsx → MultiplePrivateLinksController
          apps/web/modules/event-types/components/tabs/advanced/CustomEventTypeModal.tsx → CustomEventTypeModal, CustomEventTypeModalForm
          apps/web/modules/event-types/components/tabs/advanced/DisableReschedulingController.tsx → DisableReschedulingController
          apps/web/modules/event-types/components/tabs/advanced/EventAdvancedTab.tsx → CalendarSettings, DestinationCalendarSettings, EventAdvancedTab, render
          apps/web/modules/event-types/components/tabs/advanced/FormBuilder.tsx → (anonymous), FieldEditDialog, FormBuilder2
          apps/web/modules/event-types/components/tabs/advanced/RequiresConfirmationController.tsx → RequiresConfirmationController
          apps/web/modules/event-types/components/tabs/apps/EventAppsTab.tsx → EventAppsTab
          apps/web/modules/event-types/components/tabs/availability/EventAvailabilityTab.tsx → (anonymous), EventTypeSchedule, TeamAvailability, TeamMemberSchedule, useCommonScheduleState, useRestrictionScheduleState
          apps/web/modules/event-types/components/tabs/availability/EventAvailabilityTabWebWrapper.tsx → EventAvailabilityTabWebWrapper
          apps/web/modules/event-types/components/tabs/setup/EventSetupTab.tsx → EventSetupTab
          apps/web/modules/event-types/components/tabs/webhooks/EventWebhooksTab.tsx → EventWebhooksTab
          apps/web/modules/form-builder/components/FormBuilderField.tsx → FormBuilderField
          apps/web/modules/onboarding/components/EmailInviteForm.tsx → EmailInviteForm
          apps/web/modules/onboarding/personal/settings/personal-settings-view.tsx → PersonalSettingsView
          apps/web/modules/schedules/components/NewScheduleButton.tsx → NewScheduleButton
          apps/web/modules/settings/components/BookerLayoutSelector.tsx → BookerLayoutSelector
          apps/web/modules/settings/my-account/appearance-view.tsx → AppearanceView
          apps/web/modules/settings/my-account/general-view.tsx → GeneralView
          apps/web/modules/settings/my-account/profile-view.tsx → ProfileForm, ProfileView
          apps/web/modules/settings/oauth/create/OAuthClientCreateModal.tsx → OAuthClientCreateDialog
          apps/web/modules/settings/oauth/view/OAuthClientDetailsDialog.tsx → OAuthClientDetailsDialog
          apps/web/modules/settings/outOfOffice/CreateOrEditOutOfOfficeModal.tsx → CreateOrEditOutOfOfficeEntryModal
          apps/web/modules/settings/security/password-view.tsx → PasswordView
          apps/web/modules/signup-view.tsx → Signup, UsernameField
          apps/web/modules/users/components/UserForm.tsx → UserForm
          apps/web/modules/users/components/UserTable/EditSheet/EditUserForm.tsx → EditForm
          apps/web/modules/webhooks/components/WebhookForm.tsx → WebhookForm
          apps/web/modules/webhooks/components/WebhookTestDisclosure.tsx → WebhookTestDisclosure
          packages/features/apps/components/AppSetDefaultLinkDialog.tsx → AppSetDefaultLinkDialog
          packages/features/apps/hooks/useAppsData.ts → useAppsData
          packages/features/bookings/Booker/hooks/useBookingForm.ts → useBookingForm
          packages/features/eventtypes/components/AssignAllTeamMembers.tsx → AssignAllTeamMembers
          packages/features/eventtypes/components/BulkEditDefaultForEventsModal.tsx → BulkEditDefaultForEventsModal
          packages/features/eventtypes/components/dialogs/HostEditDialogs.tsx → PriorityDialog, WeightDialog
          packages/features/eventtypes/components/tabs/limits/EventLimitsTab.tsx → EventLimitsTab, IntervalLimitsManager, MinimumBookingNoticeInput2, RangeLimitRadioItem
          packages/features/eventtypes/components/tabs/limits/MaxActiveBookingsPerBookerController.tsx → MaxActiveBookingsPerBookerController
          packages/features/eventtypes/components/tabs/recurring/RecurringEventController.tsx → RecurringEventController
          packages/features/form-builder/useShouldBeDisabledDueToPrefill.tsx → useShouldBeDisabledDueToPrefill
          packages/features/schedules/components/DateOverrideInputDialog.tsx → DateOverrideForm
          packages/features/schedules/components/ScheduleComponent.tsx → (anonymous), CopyButton, DayRanges, ScheduleDay
          packages/platform/atoms/availability/AvailabilitySettings.tsx → AvailabilitySettings2, DateOverride, useExcludedDates
          packages/platform/atoms/connect/apple/AppleConnect.tsx → AppleConnect
          packages/platform/atoms/create-schedule/CreateScheduleForm.tsx → CreateScheduleForm
          packages/platform/atoms/event-types/hooks/useEventTypeForm.ts → useEventTypeForm
          packages/platform/atoms/event-types/wrappers/EventAvailabilityTabPlatformWrapper.tsx → EventAvailabilityTabPlatformWrapper
          packages/platform/atoms/hooks/event-types/private/useCreateEventTypeForm.ts → useCreateEventTypeForm
          packages/ui/components/address/fields.tsx → InputField2, PlainForm, TextField3
          packages/ui/components/form/inputs/Form.tsx → PlainForm
          packages/ui/components/form/inputs/HintOrErrors.tsx → HintsOrErrors
          packages/ui/components/form/inputs/Input.tsx → TextField
          packages/ui/components/form/inputs/MultiOptionInput.tsx → MultiOptionInput
   37%  @next/third-parties  (22/59 fns run, 37 never run) · e.g. GoogleAnalytics, GoogleMapsEmbed, GoogleTagManager, ThirdPartyScriptEmbed$1…
          apps/web/components/GTM.tsx → GoogleTagManagerComponent
   38%  stripe  (131/342 fns run, 211 never run) · e.g. _addHeadersDirectlyToObject, _defaultIdempotencyKey, _errorHandler, _generateConnectionErrorMessage…
          apps/api/v2/src/modules/stripe/utils/newStripeInstance.ts → (module scope)
          packages/app-store/_utils/stripe.ts → (module scope)
          packages/app-store/stripepayment/lib/PaymentService.ts → constructor
          packages/app-store/stripepayment/lib/server.ts → (module scope)
   39%  react-timezone-select  (364/922 fns run, 558 never run, 1 file(s) never loaded) · e.g. $, $r, $t, A…
          packages/features/timezone/components/TimezoneSelectComponent.tsx → TimezoneSelectComponent
   39%  entities  (54/138 fns run, 84 never run) · e.g. addToNumericResult, decode, decode$1, decodeCodePoint…
          packages/emails/templates/_base-email.ts → sendEmail
   39%  @vercel/functions  (21/54 fns run, 33 never run) · e.g. CITY_HEADER_NAME, COUNTRY_HEADER_NAME, EMOJI_FLAG_UNICODE_STARTING_POSITION, IP_HEADER_NAME…
          packages/features/auth/lib/next-auth-options.ts → signIn
   40%  @trpc/react-query  (36/91 fns run, 55 never run, 3 file(s) never loaded) · e.g. cancel, cancelQuery, createQueryUtilsProxy, createUseQueries…
          apps/web/app/_trpc/trpc.ts → (module scope)
          apps/web/modules/event-types/components/EventTypeWebWrapper.tsx → onError
   41%  date-fns  (1261/3086 fns run, 1825 never run, 8 file(s) never loaded) · e.g. B, D, E, G…
          apps/web/modules/blocklist/components/BlocklistEntryDetailsSheet.tsx → (anonymous)
          apps/web/modules/booking-audit/components/BookingHistory.tsx → (anonymous)
          apps/web/modules/data-table/components/filters/DateRangeFilter.tsx → DateRangeFilter
          packages/ui/components/form/date-range-picker/DateRangePicker.tsx → (anonymous), DatePickerWithRange
          packages/ui/components/form/datepicker/DatePicker.tsx → DatePicker
   41%  @googleapis/oauth2  (7/17 fns run, 10 never run) · e.g. constructor, get, oauth2, tokeninfo
          packages/app-store/_utils/oauth/updateProfilePhotoGoogle.ts → updateProfilePhotoGoogle
   42%  react-colorful  (42/99 fns run, 57 never run, 2 file(s) never loaded) · e.g. Ce, D, E, G…
          packages/ui/components/form/color-picker/colorpicker.tsx → ColorPicker
   43%  lodash  (490/1150 fns run, 660 never run, 53 file(s) never loaded) · e.g. LazyWrapper, LodashWrapper, SetCache, after…
          apps/web/components/ui/UsernameAvailability/PremiumTextfield.tsx → PremiumTextfield
          apps/web/components/ui/UsernameAvailability/UsernameTextfield.tsx → UsernameTextfield
          apps/web/modules/apps/components/AdminAppsList.tsx → AdminAppsList
          apps/web/modules/auth/forgot-password/forgot-password-view.tsx → ForgotPassword
          apps/web/modules/data-table/components/DataTable.tsx → (anonymous)
          apps/web/modules/data-table/components/DataTableWrapper.tsx → DataTableWrapper
          apps/web/modules/data-table/components/filters/AddFilterButton.tsx → (anonymous)
          apps/web/modules/data-table/components/filters/FilterPopover.tsx → FilterPopover
          apps/web/modules/data-table/contexts/DataTableFiltersContext.tsx → (anonymous)
          apps/web/modules/data-table/hooks/useColumnResizing.ts → (anonymous)
          apps/web/modules/data-table/hooks/useColumnSizingVars.ts → (anonymous)
          apps/web/modules/data-table/hooks/useDebouncedWidth.ts → (anonymous)
          apps/web/modules/data-table/hooks/useSegmentsNoop.ts → useSegmentsNoop
          apps/web/modules/settings/my-account/profile-view.tsx → (anonymous)
          apps/web/modules/users/components/UserForm.tsx → UserForm
          packages/app-store-cli/src/build.ts → (module scope)
          packages/emails/email-manager.ts → sendCancelledSeatEmailsAndSMS, sendRescheduledSeatEmailAndSMS
          packages/emails/templates/attendee-scheduled-email.ts → constructor, getNodeMailerPayload
          packages/emails/templates/organizer-scheduled-email.ts → getNodeMailerPayload
          packages/features/bookings/lib/BookingEmailSmsHandler.ts → _handleRoundRobinRescheduled
          packages/features/bookings/lib/EventManager.ts → create, processLocation, reschedule
          packages/features/bookings/lib/handleSeats/create/createNewSeat.ts → createNewSeat
          packages/features/bookings/lib/handleSeats/reschedule/attendee/attendeeRescheduleSeatedBooking.ts → attendeeRescheduleSeatedBooking
          packages/features/bookings/lib/handleSeats/reschedule/owner/combineTwoSeatedBookings.ts → combineTwoSeatedBookings
          packages/features/bookings/lib/handleSeats/reschedule/owner/moveSeatedBookingToNewTimeSlot.ts → moveSeatedBookingToNewTimeSlot
          packages/features/calendars/lib/CalendarManager.ts → (anonymous)
          packages/features/eventtypes/lib/getEventTypesByViewer.ts → getEventTypesByViewer
          packages/lib/formatCalendarEvent.ts → formatCalEvent
          packages/platform/atoms/booker/BookerPlatformWrapper.tsx → (anonymous)
          packages/platform/atoms/hooks/useOAuthFlow.ts → (module scope)
          packages/trpc/server/routers/viewer/me/updateProfile.handler.ts → updateProfileHandler
   43%  kbar  (203/475 fns run, 272 never run) · e.g. Escape, HistoryItemImpl, KBarAnimator$1, KBarResults$1…
          apps/web/modules/shell/Kbar.tsx → KBarContent, KBarRoot, KBarTrigger, RenderResults, useEventTypesAction, useUpcomingBookingsAction
   43%  sonner  (60/138 fns run, 78 never run, 1 file(s) never loaded) · e.g. Oe, Yt, ce, de…
          apps/web/components/apps/alby/Setup.tsx → AlbySetupPage
          apps/web/components/apps/applecalendar/Setup.tsx → AppleCalendarSetup
          apps/web/components/apps/btcpayserver/Setup.tsx → BTCPaySetupPage
          apps/web/components/apps/caldavcalendar/Setup.tsx → CalDavCalendarSetup
          apps/web/components/apps/exchange2013calendar/Setup.tsx → Exchange2013CalendarSetup
          apps/web/components/apps/exchange2016calendar/Setup.tsx → Exchange2016CalendarSetup
          apps/web/components/apps/exchangecalendar/Setup.tsx → ExchangeSetup
          apps/web/components/apps/hitpay/Setup.tsx → HitPaySetupPage
          apps/web/components/apps/ics-feedcalendar/Setup.tsx → ICSFeedSetup
          apps/web/components/apps/make/Setup.tsx → MakeSetup
          apps/web/components/apps/paypal/Setup.tsx → PayPalSetup
          apps/web/components/apps/sendgrid/Setup.tsx → SendgridSetup
          apps/web/modules/apps/installation/[[...step]]/step-view.tsx → OnboardingPage
          apps/web/modules/auth/verify-email-change-view.tsx → VerifyEmailChange
          apps/web/modules/bookings/components/Booker.tsx → BookerComponent
          apps/web/modules/bookings/views/bookings-single-view.tsx → Success
          apps/web/modules/getting-started/[[...step]]/onboarding-view.tsx → OnboardingPage
          apps/web/modules/onboarding/components/OnboardingLayout.tsx → OnboardingLayout
          apps/web/modules/shell/Shell.tsx → Layout
          apps/web/modules/signup-view.tsx → Signup
          apps/web/modules/users/views/users-public-view.tsx → UserPage
          packages/ui/components/layout/WizardLayout.tsx → WizardLayout
          packages/ui/components/toast/ProgressToast.tsx → hideProgressToast, onClose, showProgressToast
          packages/ui/components/toast/showToast.tsx → onClose, showToast
   43%  @otplib/core  (33/76 fns run, 43 never run) · e.g. allOptions, authenticatorEncoder, authenticatorGenerateSecret, authenticatorToken…
          packages/lib/totp.ts → totpAuthenticatorCheck, totpRawCheck
   44%  @testing-library/jest-dom  (365/830 fns run, 465 never run) · e.g. $fd680ce0c35731f5$export$2e2bcd8739ae039, F, SetLike, _arrayLikeToArray…
          apps/web/modules/test-setup.ts → (module scope)
          packages/app-store/test-setup.ts → (module scope)
          packages/ui/components/test-setup.tsx → (module scope)
   44%  pg  (252/573 fns run, 321 never run, 1 file(s) never loaded) · e.g. Client, Connection, DatabaseError, NOOP…
          packages/kysely/index.ts → (module scope)
          packages/prisma/index.ts → (module scope)
   45%  ipaddr.js  (30/67 fns run, 37 never run) · e.g. broadcastAddressFromCIDR, fromByteArray, isIPv4, isIPv6…
          packages/lib/ssrfProtection.ts → isPrivateIP, validateUrlCore
   46%  next-themes  (24/52 fns run, 28 never run) · e.g. ThemeProvider, c, d, e…
          apps/web/app/(use-page-wrapper)/refer/DubReferralsPage.tsx → DubReferralsPage
          apps/web/lib/app-providers-app-dir.tsx → CalcomThemeProvider
          apps/web/lib/app-providers.tsx → CalcomThemeProvider
          packages/lib/hooks/useTheme.ts → useTheme
   50%  @tanstack/react-query  (228/454 fns run, 226 never run, 1 file(s) never loaded) · e.g. HydrationBoundary, QueryErrorResetBoundary, addSignalProperty, addToEnd…
          apps/web/app/_trpc/query-client.ts → (module scope)
          apps/web/app/_trpc/trpc-provider.tsx → TrpcProvider
          apps/web/components/apps/wipemycalother/confirmDialog.tsx → ConfirmDialog
          apps/web/components/GTM.tsx → useGeolocation
          apps/web/modules/bookings/hooks/useBookings.ts → useBookings
          apps/web/modules/calendars/components/CalendarSwitch.tsx → CalendarSwitch
          apps/web/modules/schedules/hooks/useApiV2AvailableSlots.ts → useApiV2AvailableSlots
          apps/web/modules/settings/outOfOffice/OutOfOfficeEntriesList.tsx → OutOfOfficeEntriesListContent
          apps/web/modules/users/components/UsersTable.tsx → UsersTable
          packages/app-store/_utils/useAddAppMutation.ts → useAddAppMutation
          packages/platform/atoms/booker/BookerPlatformWrapper.tsx → BookerPlatformWrapperComponent
          packages/platform/atoms/cal-provider/CalOAuthProvider.tsx → (module scope), CalOAuthProvider
          packages/platform/atoms/cal-provider/CalProvider.tsx → (module scope), CalProvider
          packages/platform/atoms/connect/conferencing-apps/ConferencingAppsViewPlatformWrapper.tsx → ConferencingAppsViewPlatformWrapper
          packages/platform/atoms/connect/conferencing-apps/hooks/useAtomBulkUpdateEventTypesToDefaultLocation.ts → useAtomBulkUpdateEventTypesToDefaultLocation
          packages/platform/atoms/connect/conferencing-apps/hooks/useAtomGetEventTypes.ts → useAtomGetEventTypes
          packages/platform/atoms/connect/conferencing-apps/hooks/useAtomsGetInstalledConferencingApps.ts → useAtomsGetInstalledConferencingApps
          packages/platform/atoms/connect/conferencing-apps/hooks/useConnect.ts → useConnectNonOauthApp, useGetZoomOauthAuthUrl, useOffice365GetOauthAuthUrl
          packages/platform/atoms/connect/conferencing-apps/hooks/useDeleteCredential.ts → useDeleteCredential
          packages/platform/atoms/connect/conferencing-apps/hooks/useGetDefaultConferencingApp.ts → useGetDefaultConferencingApp
          packages/platform/atoms/connect/conferencing-apps/hooks/useUpdateUserDefaultConferencingApp.ts → useUpdateUserDefaultConferencingApp
          packages/platform/atoms/event-types/hooks/useAddVerifiedEmail.ts → useAddVerifiedEmail
          packages/platform/atoms/event-types/hooks/useAtomEventTypeAppIntegration.ts → useAtomsEventTypeById
          packages/platform/atoms/event-types/hooks/useAtomEventTypeById.ts → useAtomsEventTypeById
          packages/platform/atoms/event-types/hooks/useAtomEventTypePaymentInfo.ts → useAtomsEventTypePaymentInfo
          packages/platform/atoms/event-types/hooks/useAtomGetAllEventTypes.ts → useAtomGetAllEventTypes
          packages/platform/atoms/event-types/hooks/useAtomHostSchedules.ts → useAtomHostSchedules
          packages/platform/atoms/event-types/hooks/useAtomUpdateEventType.ts → useAtomUpdateEventType
          packages/platform/atoms/event-types/hooks/useGetVerifiedEmails.ts → useGetVerifiedEmails
          packages/platform/atoms/event-types/wrappers/EventTypePlatformWrapper.tsx → EventTypePlatformWrapper2
          packages/platform/atoms/hooks/bookings/useBooking.ts → useBooking
          packages/platform/atoms/hooks/bookings/useBookings.ts → useBookings
          packages/platform/atoms/hooks/bookings/useCancelBooking.ts → useCancelBooking
          packages/platform/atoms/hooks/bookings/useCreateBooking.ts → useCreateBooking
          packages/platform/atoms/hooks/bookings/useCreateRecurringBooking.ts → useCreateRecurringBooking
          packages/platform/atoms/hooks/bookings/useGetBookingForReschedule.ts → useGetBookingForReschedule
          packages/platform/atoms/hooks/calendars/useAddSelectedCalendar.ts → useAddSelectedCalendar
          packages/platform/atoms/hooks/calendars/useDeleteCalendarCredentials.ts → useDeleteCalendarCredentials
          packages/platform/atoms/hooks/calendars/useRemoveSelectedCalendar.ts → useRemoveSelectedCalendar
          packages/platform/atoms/hooks/calendars/useUpdateDestinationCalendars.ts → useUpdateDestinationCalendars
          packages/platform/atoms/hooks/connect/useCheck.ts → useCheck
          packages/platform/atoms/hooks/connect/useConnect.ts → useGetRedirectUrl, useSaveCalendarCredentials
          packages/platform/atoms/hooks/event-types/private/useCreateEventType.ts → useCreateEventType
          packages/platform/atoms/hooks/event-types/private/useDeleteEventTypeById.ts → useDeleteEventTypeById
          packages/platform/atoms/hooks/event-types/private/useEventTypeById.ts → useEventTypeById
          packages/platform/atoms/hooks/event-types/public/useAtomGetPublicEvent.tsx → useAtomGetPublicEvent
          packages/platform/atoms/hooks/event-types/public/useEventType.ts → useEventType
          packages/platform/atoms/hooks/event-types/public/useEventTypes.ts → useEventTypes
          packages/platform/atoms/hooks/organizations/bookings/useOrganizationBookings.ts → useOrganizationBookings
          packages/platform/atoms/hooks/organizations/bookings/useOrganizationUserBookings.ts → useOrganizationUserBookings
          packages/platform/atoms/hooks/schedules/useAtomCreateSchedule.ts → useAtomCreateSchedule
          packages/platform/atoms/hooks/schedules/useAtomDuplicateSchedule.ts → useAtomDuplicateSchedule
          packages/platform/atoms/hooks/schedules/useAtomGetAllSchedules.ts → useAtomGetAllSchedules
          packages/platform/atoms/hooks/schedules/useAtomSchedule.ts → useAtomSchedule
          packages/platform/atoms/hooks/schedules/useAtomUpdateSchedule.ts → useAtomUpdateSchedule
          packages/platform/atoms/hooks/schedules/useDeleteSchedule.ts → useDeleteSchedule
          packages/platform/atoms/hooks/schedules/useSchedule.ts → useSchedule
          packages/platform/atoms/hooks/schedules/useSchedules.ts → useSchedules
          packages/platform/atoms/hooks/schedules/useUpdateSchedule.ts → useUpdateSchedule
          packages/platform/atoms/hooks/stripe/useCheck.ts → useCheck
          packages/platform/atoms/hooks/stripe/useConnect.ts → useGetRedirectUrl
          packages/platform/atoms/hooks/useAvailableSlots.ts → useAvailableSlots
          packages/platform/atoms/hooks/useCalendarsBusyTimes.ts → useCalendarsBusyTimes
          packages/platform/atoms/hooks/useConnectedCalendars.tsx → useConnectedCalendars
          packages/platform/atoms/hooks/useDeleteSelectedSlot.ts → useDeleteSelectedSlot
          packages/platform/atoms/hooks/useEventTypesList.tsx → useEventTypesList
          packages/platform/atoms/hooks/useGetCityTimezones.ts → useGetCityTimezones
          packages/platform/atoms/hooks/useMe.ts → useMe
          packages/platform/atoms/hooks/useReserveSlot.ts → useReserveSlot
          packages/platform/atoms/hooks/useScheduleByEventSlug.tsx → useScheduleByEventSlug
          packages/platform/atoms/hooks/useUpdateUserTimezone.ts → useUpdateUserTimezone
          packages/platform/atoms/hooks/useVerifyCode.ts → useVerifyCode
          packages/platform/atoms/hooks/useVerifyEmail.ts → useVerifyEmail
   52%  superjson  (188/359 fns run, 171 never run, 1 file(s) never loaded) · e.g. __assign, __read2, __read3, __spreadArray…
          apps/web/app/_trpc/trpc-client.ts → (module scope)
          packages/lib/unstable_cache/unstable_cache.ts → (anonymous), wrap
          packages/trpc/react/trpc.ts → (module scope), config
          packages/trpc/server/trpc.ts → (module scope)
   52%  @trpc/client  (91/174 fns run, 83 never run, 1 file(s) never loaded) · e.g. cancel, clientCallTypeToProcedureType, complete, constructor…
          apps/web/app/_trpc/query-client.ts → isTRPCClientError
          apps/web/app/_trpc/trpc-client.ts → (anonymous), (module scope)
          apps/web/modules/connect-and-join/connect-and-join-view.tsx → onError
          apps/web/modules/event-types/views/event-types-listing-view.tsx → onError
          packages/trpc/react/trpc.ts → (anonymous), config
   52%  marked  (70/135 fns run, 65 never run, 1 file(s) never loaded) · e.g. blockquote, br, checkbox, code…
          packages/platform/atoms/lib/markdownToSafeHTML.ts → markdownToSafeHTML
   56%  jsonwebtoken  (162/291 fns run, 129 never run) · e.g. DataStream, NotBeforeError, SafeBuffer, SignStream…
          packages/features/auth/lib/oAuthAuthorization.ts → isAuthorized
          packages/features/oauth/services/OAuthService.ts → createTokens, verifyRefreshToken
   56%  accept-language-parser  (5/9 fns run, 4 never run) · e.g. isString, pick
          packages/features/auth/lib/getLocale.ts → getLocale
          packages/features/auth/lib/getLocaleFromRequest.ts → getLocaleFromRequest
   57%  @lexical/html  (8/14 fns run, 6 never run) · e.g. requireLexicalHtml_dev
          packages/ui/components/editor/plugins/ToolbarPlugin.tsx → (anonymous)
   58%  zustand  (36/62 fns run, 26 never run, 11 file(s) never loaded) · e.g. checkIfSnapshotChanged, destroy, error, getInitialState…
          apps/web/components/booking/actions/BookingActionsStoreProvider.tsx → useBookingActionsStoreContext
          apps/web/components/booking/actions/store.ts → createBookingActionsStore
          apps/web/modules/bookings/components/AvailableTimesHeader.tsx → AvailableTimesHeader
          apps/web/modules/bookings/components/Booker.tsx → BookerComponent
          apps/web/modules/bookings/components/BookerWebWrapper.tsx → BookerWebWrapperComponent
          apps/web/modules/bookings/components/DatePicker.tsx → DatePicker
          apps/web/modules/bookings/components/EventMeta.tsx → EventMeta
          apps/web/modules/bookings/components/SlotSelectionModalHeader.tsx → SlotSelectionModalHeader
          apps/web/modules/bookings/hooks/useBookings.ts → useBookings
          apps/web/modules/bookings/hooks/useCalendars.ts → useCalendars
          apps/web/modules/bookings/hooks/useOverlayCalendar.ts → useOverlayCalendar
          apps/web/modules/bookings/hooks/useSlots.ts → useSlots
          apps/web/modules/bookings/store/bookingDetailsSheetStore.tsx → createBookingDetailsSheetStore, useBookingDetailsSheetStore
          apps/web/modules/calendars/weeklyview/components/blocking/BlockedList.tsx → BlockedList
          apps/web/modules/calendars/weeklyview/components/event/Empty.tsx → Cell
          apps/web/modules/calendars/weeklyview/components/event/EventList.tsx → EventList
          apps/web/modules/embed/components/Embed.tsx → EmailEmbed, EmbedTypeCodeAndPreviewDialogContent
          apps/web/modules/onboarding/store/onboarding-storage.ts → (module scope)
          apps/web/modules/onboarding/store/onboarding-store.ts → (module scope)
          apps/web/modules/schedules/hooks/useEvent.ts → useEvent, useScheduleForEvent
          apps/web/modules/users/components/UserTable/EditSheet/EditUserSheet.tsx → EditUserSheet
          apps/web/modules/users/components/UserTable/EditSheet/store.ts → (module scope)
          packages/features/bookings/Booker/BookerStoreProvider.tsx → useBookerStoreContext, useInitializeBookerStoreContext
          packages/features/bookings/Booker/components/OverlayCalendar/store.ts → (module scope)
          packages/features/bookings/Booker/hooks/useBookerLayout.ts → useBookerLayout
          packages/features/bookings/Booker/hooks/useBookerTime.ts → useBookerTime
          packages/features/bookings/Booker/store.ts → createBookerStore
          packages/features/bookings/components/Header.tsx → Header
          packages/features/bookings/lib/timePreferences.ts → (module scope)
          packages/features/calendars/components/DatePicker.tsx → Days
          packages/features/calendars/weeklyview/state/store.ts → createCalendarStore, useCalendarStore
          packages/features/schedules/hooks/useTimesForSchedule.ts → useTimesForSchedule
          packages/features/troubleshooter/components/EventTypeSelectComponent.tsx → EventTypeSelectComponent
          packages/features/troubleshooter/store.ts → (module scope)
          packages/platform/atoms/booker/BookerPlatformWrapper.tsx → BookerPlatformWrapperComponent
          packages/platform/atoms/calendar-view/EventTypeCalendarViewComponent.tsx → EventTypeCalendarViewComponent
          packages/platform/atoms/hooks/useSlots.ts → useSlots
   60%  react-digit-input  (9/15 fns run, 6 never run) · e.g. onClick
          apps/web/components/auth/TwoFactor.tsx → TwoFactor
          apps/web/modules/bookings/components/VerifyCodeDialog.tsx → VerifyCodeDialog
   61%  react-inlinesvg  (45/74 fns run, 29 never run, 3 file(s) never loaded) · e.g. clear, data, delete, fetchAndAddToPersistentCache…
          apps/web/app/providers.tsx → Providers
          apps/web/pages/_app.tsx → MyApp
          packages/ui/components/icon/IconSprites.tsx → IconSprites
   61%  resize-observer-polyfill  (46/75 fns run, 29 never run, 1 file(s) never loaded) · e.g. ResizeObserverEntry, broadcastActive, broadcastRect, createReadOnlyRect…
          apps/web/modules/test-setup.ts → (module scope)
   65%  @radix-ui/react-toggle-group  (61/94 fns run, 33 never run, 1 file(s) never loaded) · e.g. $d7bdfb9eb0fdf311$var$getDirectionAwareKey, $d7bdfb9eb0fdf311$var$getFocusIntent, $d7bdfb9eb0fdf311$var$wrapArray, onPressedChange
          packages/ui/components/form/toggleGroup/BooleanToggleGroup.tsx → BooleanToggleGroup2
          packages/ui/components/form/toggleGroup/ToggleGroup.tsx → (anonymous), ToggleGroup
   66%  @trpc/server  (111/167 fns run, 56 never run, 9 file(s) never loaded) · e.g. assertIsJSONRPC2OrUndefined, assertIsObject, assertIsProcedureType, assertIsRequestId…
          apps/web/app/api/defaultResponderForAppDir.ts → (anonymous)
          apps/web/app/api/link/route.ts → handler
          apps/web/app/api/verify-booking-token/route.ts → handleBookingAction
          packages/features/eventtypes/lib/getEventTypeById.ts → getEventTypeById
          packages/platform/libraries/index.ts → (module scope)
          packages/trpc/server/createNextApiHandler.ts → createNextApiHandler
          packages/trpc/server/lib/toTRPCError.ts → convertErrorWithCodeToTRPCError
          packages/trpc/server/middlewares/sessionMiddleware.ts → (anonymous)
          packages/trpc/server/onErrorHandler.ts → onErrorHandler
          packages/trpc/server/procedures/pbacProcedures.ts → (anonymous)
          packages/trpc/server/routers/loggedInViewer/addNotificationsSubscription.handler.ts → addNotificationsSubscriptionHandler
          packages/trpc/server/routers/loggedInViewer/addSecondaryEmail.handler.ts → addSecondaryEmailHandler
          packages/trpc/server/routers/loggedInViewer/connectAndJoin.handler.ts → Handler
          packages/trpc/server/routers/loggedInViewer/eventTypeOrder.handler.ts → eventTypeOrderHandler
          packages/trpc/server/routers/loggedInViewer/stripeCustomer.handler.ts → stripeCustomerHandler
          packages/trpc/server/routers/loggedInViewer/teamsAndUserProfilesQuery.handler.ts → teamsAndUserProfilesQuery
          packages/trpc/server/routers/viewer/admin/createCoupon.handler.ts → createCoupon
          packages/trpc/server/routers/viewer/admin/setSMSLockState.handler.ts → setSMSLockState
          packages/trpc/server/routers/viewer/admin/watchlist/bulkDelete.handler.ts → bulkDeleteWatchlistEntriesHandler
          packages/trpc/server/routers/viewer/admin/watchlist/create.handler.ts → createWatchlistEntryHandler
          packages/trpc/server/routers/viewer/admin/watchlist/delete.handler.ts → deleteWatchlistEntryHandler
          packages/trpc/server/routers/viewer/admin/watchlist/getDetails.handler.ts → getWatchlistEntryDetailsHandler
          packages/trpc/server/routers/viewer/apiKeys/_auth-middleware.ts → checkPermissions
          packages/trpc/server/routers/viewer/apps/appById.handler.ts → appByIdHandler
          packages/trpc/server/routers/viewer/apps/saveKeys.handler.ts → saveKeysHandler
          packages/trpc/server/routers/viewer/apps/toggle.handler.ts → toggleHandler
          packages/trpc/server/routers/viewer/apps/updateAppCredentials.handler.ts → handleCustomValidations, updateAppCredentialsHandler
          packages/trpc/server/routers/viewer/apps/updateUserDefaultConferencingApp.handler.ts → updateUserDefaultConferencingAppHandler
          packages/trpc/server/routers/viewer/auth/changePassword.handler.ts → changePasswordHandler
          packages/trpc/server/routers/viewer/auth/createAccountPassword.handler.ts → createAccountPasswordHandler
          packages/trpc/server/routers/viewer/auth/resendVerifyEmail.handler.ts → resendVerifyEmail
          packages/trpc/server/routers/viewer/auth/verifyCodeUnAuthenticated.handler.ts → verifyCodeUnAuthenticatedHandler
          packages/trpc/server/routers/viewer/auth/verifyPassword.handler.ts → verifyPasswordHandler
          packages/trpc/server/routers/viewer/availability/calendarOverlay.handler.ts → (anonymous), calendarOverlayHandler
          packages/trpc/server/routers/viewer/availability/schedule/bulkUpdateDefaultAvailability.handler.ts → bulkUpdateToDefaultAvailabilityHandler
          packages/trpc/server/routers/viewer/availability/schedule/create.handler.ts → createHandler
          packages/trpc/server/routers/viewer/availability/schedule/delete.handler.ts → deleteHandler
          packages/trpc/server/routers/viewer/availability/schedule/duplicate.handler.ts → duplicateHandler
          packages/trpc/server/routers/viewer/availability/schedule/getAllSchedulesByUserId.handler.ts → getAllSchedulesByUserIdHandler
          packages/trpc/server/routers/viewer/availability/team/listTeamAvailability.handler.ts → getInfoForAllTeams
          packages/trpc/server/routers/viewer/availability/user.handler.ts → userHandler
          packages/trpc/server/routers/viewer/bookings/addGuests.handler.ts → getBooking, getOrganizerData, sanitizeAndFilterGuests, updateCalendarEvent, validateGuestsFieldEnabled, validateUserPermissions
          packages/trpc/server/routers/viewer/bookings/confirm.handler.ts → confirmHandler
          packages/trpc/server/routers/viewer/bookings/editLocation.handler.ts → getLocationInEvtFormatOrThrow
          packages/trpc/server/routers/viewer/bookings/get.handler.ts → getAttendeeEmailsFromUserIdsFilter, getBookings, getEventTypeIdsFromEventTypeIdsFilter
          packages/trpc/server/routers/viewer/bookings/getBookingHistory.handler.ts → getBookingHistoryHandler
          packages/trpc/server/routers/viewer/bookings/hasWrongAssignmentReport.handler.ts → hasWrongAssignmentReportHandler
          packages/trpc/server/routers/viewer/bookings/reportBooking.handler.ts → reportBookingHandler
          packages/trpc/server/routers/viewer/bookings/reportWrongAssignment.handler.ts → reportWrongAssignmentHandler
          packages/trpc/server/routers/viewer/bookings/requestReschedule.handler.ts → requestRescheduleHandler
          packages/trpc/server/routers/viewer/bookings/updateWrongAssignmentReportStatus.handler.ts → updateWrongAssignmentReportStatusHandler
          packages/trpc/server/routers/viewer/bookings/util.ts → (anonymous)
          packages/trpc/server/routers/viewer/calendars/setDestinationCalendar.handler.ts → setDestinationCalendarHandler
          packages/trpc/server/routers/viewer/calVideo/getCalVideoRecordings.handler.ts → getCalVideoRecordingsHandler
          packages/trpc/server/routers/viewer/calVideo/getDownloadLinkOfCalVideoRecordings.handler.ts → getDownloadLinkOfCalVideoRecordingsHandler
          packages/trpc/server/routers/viewer/calVideo/getMeetingInformation.handler.ts → getMeetingInformationHandler
          packages/trpc/server/routers/viewer/eventTypes/bulkUpdateToDefaultLocation.handler.ts → bulkUpdateToDefaultLocationHandler
          packages/trpc/server/routers/viewer/eventTypes/getActiveOnOptions.handler.ts → getActiveOnOptions
          packages/trpc/server/routers/viewer/eventTypes/getHashedLink.handler.ts → getHashedLinkHandler
          packages/trpc/server/routers/viewer/eventTypes/getHostsWithLocationOptions.handler.ts → getHostsWithLocationOptionsHandler
          packages/trpc/server/routers/viewer/eventTypes/getUserEventGroups.handler.ts → getUserEventGroups
          packages/trpc/server/routers/viewer/eventTypes/heavy/create.handler.ts → createHandler
          packages/trpc/server/routers/viewer/eventTypes/heavy/duplicate.handler.ts → duplicateHandler
          packages/trpc/server/routers/viewer/eventTypes/heavy/update.handler.ts → updateHandler
          packages/trpc/server/routers/viewer/eventTypes/massApplyHostLocation.handler.ts → massApplyHostLocationHandler
          packages/trpc/server/routers/viewer/eventTypes/util.ts → (anonymous), ensureEmailOrPhoneNumberIsPresent
          packages/trpc/server/routers/viewer/holidays/toggleHoliday.handler.ts → toggleHolidayHandler
          packages/trpc/server/routers/viewer/holidays/updateSettings.handler.ts → updateSettingsHandler
          packages/trpc/server/routers/viewer/me/updateProfile.handler.ts → updateProfileHandler
          packages/trpc/server/routers/viewer/oAuth/deleteClient.handler.ts → deleteClientHandler
          packages/trpc/server/routers/viewer/oAuth/generateAuthCode.handler.ts → generateAuthCodeHandler
          packages/trpc/server/routers/viewer/oAuth/getClientForAuthorization.handler.ts → getClientForAuthorizationHandler
          packages/trpc/server/routers/viewer/oAuth/updateClient.handler.ts → updateClientHandler
          packages/trpc/server/routers/viewer/ooo/outOfOfficeCreateOrUpdate.handler.ts → outOfOfficeCreateOrUpdate
          packages/trpc/server/routers/viewer/ooo/outOfOfficeEntriesList.handler.ts → outOfOfficeEntriesList
          packages/trpc/server/routers/viewer/ooo/outOfOfficeEntryDelete.handler.ts → outOfOfficeEntryDelete
          packages/trpc/server/routers/viewer/payments/chargeCard.handler.ts → chargeCardHandler
          packages/trpc/server/routers/viewer/slots/reserveSlot.handler.ts → reserveSlotHandler
          packages/trpc/server/routers/viewer/slots/util.ts → (anonymous), _getAvailableSlots, _getDynamicEventType, _mapWithinBoundsSlotsToDate, getEventTypeId
          packages/trpc/server/routers/viewer/users/_router.ts → (anonymous)
          packages/trpc/server/routers/viewer/webhook/create.handler.ts → createHandler
          packages/trpc/server/routers/viewer/webhook/edit.handler.ts → editHandler
          packages/trpc/server/routers/viewer/webhook/util.ts → (anonymous)
          packages/trpc/server/trpc.ts → (module scope)
   67%  bcp-47-match  (4/6 fns run, 2 never run)
          packages/features/auth/lib/getLocale.ts → getLocale
          packages/trpc/server/routers/viewer/i18n/i18n.schema.ts → (anonymous)
   68%  @radix-ui/react-popover  (282/412 fns run, 130 never run, 1 file(s) never loaded) · e.g. $5cb92bef7577960e$var$handleAndDispatchCustomEvent, $8927f6f2acc4f386$export$6d1a0317bde7de7f, $cf1ac5d9fe0e8206$export$79d62cd4e10a3fd0, $cf1ac5d9fe0e8206$var$isNotNull…
          packages/ui/components/form/color-picker/colorpicker.tsx → ColorPicker
          packages/ui/components/form/date-range-picker/DateRangePicker.tsx → DatePickerWithRange
          packages/ui/components/form/datepicker/DatePicker.tsx → DatePicker
          packages/ui/components/popover/AnimatedPopover.tsx → AnimatedPopover
          packages/ui/components/popover/MeetingTimeInTimezones.tsx → MeetingTimeInTimezones
          packages/ui/components/popover/Popover.tsx → (anonymous), (module scope)
   69%  dayjs  (297/431 fns run, 134 never run) · e.g. $, M, MM, _…
          packages/dayjs/index.ts → (module scope)
   69%  @radix-ui/react-slot  (9/13 fns run, 4 never run, 1 file(s) never loaded) · e.g. Slottable, propName
          packages/platform/atoms/src/components/ui/button.tsx → (anonymous)
          packages/ui/components/section/section.tsx → Description, Title
   70%  @otplib/plugin-thirty-two  (7/10 fns run, 3 never run) · e.g. encode, keyEncoder, quintetCount
          packages/lib/totp.ts → totpAuthenticatorCheck
   71%  cmdk  (82/116 fns run, 34 never run, 1 file(s) never loaded) · e.g. $, CommandDialog, CommandEmpty, CommandGroup…
          packages/ui/components/command/Command.tsx → (anonymous), (module scope)
   71%  class-variance-authority  (5/7 fns run, 2 never run, 1 file(s) never loaded)
          apps/web/modules/calendars/weeklyview/components/event/Event.tsx → (module scope)
          packages/coss-ui/src/components/alert.tsx → (module scope)
          packages/coss-ui/src/components/badge.tsx → (module scope)
          packages/coss-ui/src/components/button.tsx → (module scope)
          packages/coss-ui/src/components/empty.tsx → (module scope)
          packages/coss-ui/src/components/group.tsx → (module scope)
          packages/coss-ui/src/components/input-group.tsx → (module scope)
          packages/coss-ui/src/components/select.tsx → (module scope)
          packages/coss-ui/src/components/sidebar.tsx → (module scope)
          packages/coss-ui/src/components/toggle.tsx → (module scope)
          packages/platform/atoms/src/components/ui/button.tsx → (module scope)
          packages/platform/atoms/src/components/ui/toast.tsx → (module scope)
          packages/ui/components/alert/Alert.tsx → (module scope)
          packages/ui/components/avatar/Avatar.tsx → (module scope)
          packages/ui/components/badge/Badge.tsx → (module scope)
          packages/ui/components/button/Button.tsx → (module scope)
          packages/ui/components/card/Card.tsx → (module scope)
          packages/ui/components/dialog/Dialog.tsx → (module scope)
          packages/ui/components/form/inputs/TextField.tsx → (module scope)
          packages/ui/components/progress-bar/ProgressBar.tsx → (module scope)
   72%  @testing-library/react  (62/86 fns run, 24 never run, 1 file(s) never loaded) · e.g. asFragment, blur, configure, createLegacyRoot…
          packages/app-store/test-setup.ts → (anonymous)
          packages/features/form-builder/testUtils.ts → (anonymous), addOption, close, deleteField, fillInFieldIdentifier, fillInFieldLabel, fillInOption, fillInPrice…
          packages/ui/components/test-setup.tsx → (anonymous)
   72%  @radix-ui/react-avatar  (26/36 fns run, 10 never run, 1 file(s) never loaded) · e.g. createScope, useComposedScopes, useScope
          packages/ui/components/avatar/Avatar.tsx → Avatar
   73%  @radix-ui/react-dialog  (179/246 fns run, 67 never run, 1 file(s) never loaded) · e.g. $5cb92bef7577960e$var$handleAndDispatchCustomEvent, $8927f6f2acc4f386$export$6d1a0317bde7de7f, $d3863c46a17e8a28$var$findVisible, $d3863c46a17e8a28$var$getTabbableEdges…
          packages/features/components/controlled-dialog/index.tsx → Dialog
          packages/ui/components/dialog/ConfirmationDialogContent.tsx → ConfirmationContent
          packages/ui/components/dialog/Dialog.tsx → (anonymous), Dialog, DialogClose
          packages/ui/components/sheet/Sheet.tsx → (anonymous), (module scope), Sheet
   73%  @radix-ui/react-switch  (35/48 fns run, 13 never run, 1 file(s) never loaded) · e.g. createScope, useComposedScopes, useScope
          packages/platform/atoms/src/components/ui/switch.tsx → (anonymous), (module scope)
          packages/ui/components/form/switch/Switch.tsx → Switch
   78%  @evyweb/ioctopus  (28/36 fns run, 8 never run, 1 file(s) never loaded) · e.g. bind, runInScope, toFunction, toHigherOrderFunction…
          packages/features/di/di.ts → (module scope)
          packages/features/di/shared/services/logger.service.ts → (module scope)
          packages/features/di/shared/services/tasker.service.ts → (module scope)
          packages/features/di/shared/services/triggerDevLogger.service.ts → (module scope)
          packages/features/di/watchlist/containers/watchlist.ts → (module scope)
          packages/features/di/watchlist/modules/Watchlist.module.ts → (module scope)
          packages/features/di/webhooks/containers/webhook.ts → (module scope)
          packages/features/di/webhooks/modules/BookingWebhookDataFetcher.module.ts → (module scope)
          packages/features/di/webhooks/modules/OOOWebhookDataFetcher.module.ts → (module scope)
          packages/features/di/webhooks/modules/PaymentWebhookDataFetcher.module.ts → (module scope)
          packages/features/di/webhooks/modules/RecordingWebhookDataFetcher.module.ts → (module scope)
          packages/features/di/webhooks/modules/Webhook.module.ts → (module scope)
          packages/features/di/webhooks/modules/WebhookTaskConsumer.module.ts → (module scope)
          packages/features/di/webhooks/repositories/Webhook.repository.ts → (module scope)
          packages/features/di/webhooks/services/Webhook.service.ts → (module scope)
   80%  @radix-ui/react-id  (4/5 fns run, 1 never run, 1 file(s) never loaded)
          packages/ui/components/address/fields.tsx → InputField2, TextField3
          packages/ui/components/form/checkbox/Checkbox.tsx → (anonymous)
          packages/ui/components/form/select/Select.tsx → SelectField2
          packages/ui/components/form/switch/Switch.tsx → Switch
          packages/ui/components/form/toggleGroup/BooleanToggleGroup.tsx → BooleanToggleGroupField2
          packages/ui/components/radio/RadioAreaGroup.tsx → RadioArea
   83%  @otplib/plugin-crypto  (5/6 fns run, 1 never run) · e.g. createRandomBytes
          packages/lib/totp.ts → totpAuthenticatorCheck, totpRawCheck
   84%  tailwind-merge  (67/80 fns run, 13 never run, 1 file(s) never loaded) · e.g. extendTailwindMerge, get, isNever, isPercent…
          packages/coss-ui/src/lib/utils.ts → cn
          packages/platform/atoms/src/lib/utils.ts → cn
          packages/ui/classNames.ts → classNames
   84%  short-uuid  (16/19 fns run, 3 never run) · e.g. enlargeUUID, generate, toUUID
          packages/emails/lib/getICalUID.ts → getICalUID
          packages/features/bookings/lib/handleSeats/create/createNewSeat.ts → addSeatToBooking
          packages/features/bookings/lib/handleSeats/reschedule/owner/combineTwoSeatedBookings.ts → combineTwoSeatedBookings
          packages/features/bookings/lib/service/RegularBookingService.ts → (module scope), handler
          packages/features/conferencing/lib/videoClient.ts → (module scope)
          packages/lib/builders/CalendarEvent/builder.ts → (module scope)
          packages/lib/CalEventParser.ts → (module scope)
          packages/lib/generateHashedLink.ts → generateHashedLink
   86%  otplib  (6/7 fns run, 1 never run) · e.g. get
          apps/web/app/api/auth/two-factor/totp/setup/route.ts → postHandler
          packages/features/auth/lib/verifyEmail.ts → sendEmailVerificationByCode
   88%  react-sticky-box  (28/32 fns run, 4 never run) · e.g. emptyHandler, handler
          apps/web/modules/bookings/components/Booker.tsx → BookerComponent
   90%  @hookform/error-message  (9/10 fns run, 1 never run) · e.g. get
          apps/web/components/dialog/EditLocationDialog.tsx → (anonymous)
          apps/web/modules/event-types/components/locations/CalVideoSettings.tsx → CalVideoSettings
          apps/web/modules/event-types/components/locations/DefaultLocationSettings.tsx → DefaultLocationSettings
          apps/web/modules/event-types/components/locations/Locations.tsx → (anonymous)
          apps/web/modules/form-builder/components/FormBuilderField.tsx → render
  … +4 more (full set in coverage-report.json)

NEVER LOADED by any test (34) — extracted but unexercised, so covtrim can't classify their code:
  @axiomhq/winston, @dub/analytics, @dub/embed-react, @getalby/sdk, @glidejs/glide, @nestjs/bull, @nestjs/jwt, @nestjs/passport, @radix-ui/react-dialog-atoms, @radix-ui/react-popover-atoms, @radix-ui/react-toast, @radix-ui/react-tooltip-atoms, @sendgrid/client, @stripe/react-stripe-js, @tryvital/vital-node, @vercel/edge-config, class-transformer, class-validator, connect, cron, fs-extra, http-proxy-middleware, ink-select-input, ink-text-input, ioredis, meow, queue, react-calendar, react-date-picker, remove-markdown … +4

The standing work order built from it — the ranked prompt a coding agent takes whole:

.chainstrip/coverage-prompt.md — the standing work order: 100 testable targets (7 UNLOCK · 93 CLASSIFY) and 32 reasoned skips (printed 2026-07-29; scroll inside)
# Test-writing task — close chainstrip coverage gaps for cal.diy

You are an expert test author. Write tests that exercise the dependencies below by testing
**this project's own functions that call them**. The goal is **attack surface removed —
safely**. Each dep is tagged by exactly what a test buys, and the list is ordered by payoff:

- **UNLOCK <size>** — the dep ships whole or under weaker evidence today (no test loads it,
  or covtrim's trim rolled back). A test lets chainstrip measure/remove it: NEW surface
  reduction. These are the biggest wins.
- **CLASSIFY <size>** — functions reachable from your imports that no test ever executed.
  A test converts unknown risk into truth: what it executes is proven LIVE (correctly kept
  — a false-dead averted); what stays unexecuted stays held. Safety value, not bytes.
- **FIRM UP <size>** — chainstrip already shipped stubs on reachable-but-unexecuted
  functions (aggressive mode). A test on those paths retires the false-dead risk (or
  catches the live one before production does). De-risking, not new bytes.

## How to write the tests
- Test runner: **vitest** (`yarn test`). Match this repo's existing tests —
  open a neighbouring `*.test.*` first and copy its import style, setup, and mocking.
- Do NOT test the dependency's API directly. Test **your** function at the call site listed
  under each dep — exercising your REAL, used path is what proves the app works without the
  dependency's unused code.
- **DETERMINISM IS THE #1 REQUIREMENT — a flaky test is WORSE than no test.** chainstrip
  removes a dependency's unexercised functions only if every test that touches that dep
  passes *repeatably* against the trimmed copy; if a test flakes even once, it REVERTS the
  removal — so a timing-flaky test will DESTROY eliminations the existing suite already had.
  Therefore: never use `setTimeout`, arbitrary `await new Promise(r => setTimeout(r,0))`, or
  any wall-clock wait to let async work "settle." Instead **`await` the real promise**, or
  **capture synchronously at call time** (e.g. record the argument inside a `sendMail`/handler
  spy when it is *called*, not after it resolves). If a value is produced asynchronously,
  await the actual operation — don't guess a delay.
- You do NOT need to reach the "never-run functions" listed per dep — chainstrip will remove
  them *because* they're unexercised. Reaching them keeps them in the artifact. Just cover the
  path your code genuinely uses, cleanly. (The list is shown only so you recognise which
  behaviour is already covered vs not.)
- Mock only external I/O (network, DB, clock) the way nearby tests do. Every test must assert
  real behaviour, not just call-and-ignore.
- Put each test next to the file under test. Run each file you write multiple times
  (`yarn test <path>`, twice) to confirm it is NOT flaky before moving on.
- Do NOT conclude a location can't run under the test runner by reading workspace/config
  files — two prior sessions skipped valid targets that way. VERIFY empirically (run the
  runner's list command on your intended path, or run a trivial probe test there); only a
  verified exclusion counts, and report it as such. Entries below include "Runner evidence"
  — a traced test that already runs near the call site — when we have it.

## Priority worklist
⚠ = has a live CVE AND is under-tested — do these first.

### 1. ⚠ `next-auth` — CLASSIFY 259KB — 259KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)  ⚠ 3 live CVEs (CRITICAL)
Runner evidence: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (287 fns, 215KB)`, `react/index.js (78 fns, 35KB)`, `jwt/index.js (8 fns, 5KB)`, `providers/email.js (2 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/app/(use-page-wrapper)/auth/forgot-password/page.tsx` → `ServerPage`
- `apps/web/app/(use-page-wrapper)/settings/(settings-layout)/SettingsLayoutAppDirClient.tsx` → `useTabs`
- `apps/web/app/providers.tsx` → `Providers`
- `apps/web/components/apps/btcpayserver/Setup.tsx` → `BTCPaySetupPage`
- `apps/web/components/apps/hitpay/Setup.tsx` → `HitPaySetupPage`
- `apps/web/components/setup/AdminUser.tsx` → `(anonymous)`
- `apps/web/components/ui/UsernameAvailability/PremiumTextfield.tsx` → `PremiumTextfield`
- `apps/web/components/ui/UsernameAvailability/UsernameTextfield.tsx` → `UsernameTextfield`
- `apps/web/lib/app-providers.tsx` → `CustomI18nextProvider`
- `apps/web/modules/apps/[slug]/setup/setup-view.tsx` → `SetupInformation`
- `apps/web/modules/auth/hooks/useRedirectToLoginIfUnauthenticated.tsx` → `useRedirectToLoginIfUnauthenticated`
- `apps/web/modules/auth/login-view.tsx` → `onClick`, `onSubmit`
- `apps/web/modules/auth/logout-view.tsx` → `Logout`
- `apps/web/modules/auth/oauth2/authorize-view.tsx` → `Authorize`
- `apps/web/modules/auth/signin-view.tsx` → `onClick`
- `apps/web/modules/auth/verify-email-change-view.tsx` → `VerifyEmailChange`
- `apps/web/modules/auth/verify-email-view.tsx` → `VerifyEmailPage`, `onClick`
- `apps/web/modules/auth/verify-view.tsx` → `sendVerificationLogin`
- `apps/web/modules/bookings/components/BookerWebWrapper.tsx` → `BookerWebWrapperComponent`
- `apps/web/modules/bookings/hooks/useEventTypes.ts` → `useEventTypes`
- `apps/web/modules/bookings/hooks/useVerifyEmail.ts` → `useVerifyEmail`
- `apps/web/modules/bookings/views/bookings-single-view.tsx` → `Success`
- `apps/web/modules/connect-and-join/connect-and-join-view.tsx` → `ConnectAndJoin`
- `apps/web/modules/data-table/components/segment/DuplicateSegmentDialog.tsx` → `DuplicateSegmentDialog`
- `apps/web/modules/data-table/components/segment/FilterSegmentSelect.tsx` → `FilterSegmentSelect`
- `apps/web/modules/data-table/components/segment/SaveFilterSegmentButton.tsx` → `SaveFilterSegmentButton`
- `apps/web/modules/embed/components/Embed.tsx` → `EmbedTypeCodeAndPreviewDialogContent`
- `apps/web/modules/event-types/components/locations/HostLocations.tsx` → `HostLocations`
- `apps/web/modules/event-types/components/tabs/setup/EventSetupTabWebWrapper.tsx` → `EventSetupTabWebWrapper`
- `apps/web/modules/filters/components/TeamsFilter.tsx` → `TeamsFilter`
- `apps/web/modules/formbricks/hooks/useFormbricks.ts` → `useFormbricks`
- `apps/web/modules/getting-started/[[...step]]/onboarding-view.tsx` → `onClick`
- `apps/web/modules/onboarding/components/OnboardingLayout.tsx` → `handleSignOut`
- `apps/web/modules/onboarding/hooks/useOnboardingCalendarEvents.ts` → `useOnboardingCalendarEvents`
- `apps/web/modules/onboarding/personal/_components/OnboardingLayout.tsx` → `handleSignOut`
- `apps/web/modules/settings/components/TimezoneChangeDialog.tsx` → `useOpenTimezoneDialog`
- `apps/web/modules/settings/my-account/appearance-view.tsx` → `AppearanceView`
- `apps/web/modules/settings/my-account/general-view.tsx` → `GeneralView`
- `apps/web/modules/settings/my-account/profile-view.tsx` → `ProfileView`, `onDeleteMeSuccessMutation`
- `apps/web/modules/settings/security/password-view.tsx` → `PasswordView`, `onSuccess`
- `apps/web/modules/settings/security/two-factor-auth-view.tsx` → `TwoFactorAuthView`, `onEnable`
- `apps/web/modules/shell/banners/useBanners.ts` → `useBannersInternal`
- `apps/web/modules/shell/Kbar.tsx` → `useUpcomingBookingsAction`
- `apps/web/modules/shell/navigation/Navigation.tsx` → `MobileNavigationContainer`
- `apps/web/modules/shell/navigation/useMobileMoreItems.ts` → `useMobileMoreItems`
- `apps/web/modules/shell/Shell.tsx` → `PublicShell`
- `apps/web/modules/shell/SideBar.tsx` → `SideBarContainer`
- `apps/web/modules/shell/TopNav.tsx` → `TopNavContainer`
- `apps/web/modules/shell/user-dropdown/ProfileDropdown.tsx` → `ProfileDropdown`
- `apps/web/modules/shell/user-dropdown/UserDropdown.tsx` → `onClick`
- `apps/web/modules/signup-view.tsx` → `signUp`
- `apps/web/modules/troubleshooter/components/LargeCalendar.tsx` → `LargeCalendar`
- `apps/web/modules/users/components/UserTable/ChangeUserRoleModal.tsx` → `ChangeUserRoleModal`
- `apps/web/modules/users/components/UserTable/DeleteMemberModal.tsx` → `DeleteMemberModal`
- `apps/web/modules/users/components/UserTable/EditSheet/EditUserForm.tsx` → `EditForm`
- `apps/web/modules/users/components/UserTable/InviteMemberModal.tsx` → `InviteMemberModal`
- `apps/web/modules/users/components/UserTable/UserListTable.tsx` → `UserListTableContent`
- `apps/web/modules/users/components/UserTable/UserTableActions.tsx` → `TableActions`
- `apps/web/modules/webhooks/views/webhook-new-view.tsx` → `NewWebhookView`
- `apps/web/pages/_app.tsx` → `MyApp`
- `apps/web/pages/api/auth/[...nextauth].ts` → `handler`
- `apps/web/server/lib/auth/login/getServerSideProps.tsx` → `getServerSideProps`
- `apps/web/server/lib/auth/signin/getServerSideProps.tsx` → `getServerSideProps`
- `packages/features/auth/lib/getLocale.ts` → `getLocale`
- `packages/features/auth/lib/getServerSession.ts` → `getServerSession`
- `packages/features/auth/lib/getSession.ts` → `getSession`
- `packages/features/auth/lib/next-auth-options.ts` → `encode`
- `packages/features/auth/PermissionContainer.tsx` → `PermissionContainer`
Existing test(s) that load `next-auth` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts`, `apps/web/modules/shell/user-dropdown/UserDropdown.test.tsx`, `apps/web/modules/users/components/AdminPasswordBanner.test.tsx`, `apps/web/pages/api/book/recurring-event.test.ts`, `packages/app-store/stripepayment/api/__tests__/portal.test.ts` … (+2 more).
Currently-unexercised functions in `next-auth` (context only — chainstrip removes these; do NOT write tests to reach them): `$`, `A`, `AccountNotLinkedError2`, `AsyncIterator`, `AzureAD`, `C`, `ErrorPage`, `F`, `Generator`, `GeneratorFunction`, `GeneratorFunctionPrototype`, `Google` … (+315 more).

### 2. ⚠ `kysely` — CLASSIFY 215KB — 215KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)  ⚠ 1 live CVE (HIGH)
Runner evidence: `packages/trpc/server/routers/viewer/bookings/confirm.handler.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/esm/index.js (534 fns, 121KB)`, `chainstrip-chunk-B38FPEcq.mjs (596 fns, 94KB)`, `dist/esm/helpers/postgres.js (1 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/kysely/utils/json/traverse/index.ts` → `traverseJSON`
- `packages/trpc/server/routers/viewer/bookings/get.handler.ts` → `(anonymous)`
Existing test(s) that load `kysely` but don't reach the functions above — **extend these**: `packages/kysely/utils/json/traverse/traverseJSON.test.ts`, `packages/trpc/server/routers/viewer/bookings/get.handler.test.ts`.
Currently-unexercised functions in `kysely` (context only — chainstrip removes these; do NOT write tests to reach them): `$asScalar`, `$asTuple`, `$assertType`, `$call`, `$castTo`, `$if`, `$narrowType`, `$notNull`, `PRIVATE_DESTROY_METHOD`, `PRIVATE_RELEASE_METHOD`, `PRIVATE_RELEASE_METHOD$1`, `PRIVATE_RESET_METHOD` … (+746 more).

### 3. ⚠ `js-yaml` — CLASSIFY 112KB — 112KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)  ⚠ 2 live CVEs (HIGH)
Runner evidence: `apps/web/lib/apps/[slug]/__tests__/parseFrontmatter.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (100 fns, 79KB)`, `dist/js-yaml.mjs (62 fns, 33KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/lib/apps/[slug]/getStaticProps.ts` → `parseFrontmatter`
Existing test(s) that load `js-yaml` but don't reach the functions above — **extend these**: `apps/web/lib/apps/[slug]/__tests__/parseFrontmatter.test.ts`, `apps/web/lib/apps/[slug]/__tests__/parseFrontmatterYamlSyntax.test.ts`.
Currently-unexercised functions in `js-yaml` (context only — chainstrip removes these; do NOT write tests to reach them): `State`, `YAMLException`, `_class`, `binary`, `blockHeader`, `camelcase`, `canonical`, `captureSegment`, `charFromCodepoint`, `chooseScalarStyle`, `codePointAt`, `compileStyleMap` … (+109 more).

### 4. ⚠ `qs` — CLASSIFY 25KB — 25KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)  ⚠ 1 live CVE (MODERATE)
Runner evidence: `apps/web/components/apps/InstallAppButtonChild.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lib/index.js (42 fns, 25KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/api/v2/src/main.ts` → `(anonymous)`, `stdin_default`
- `apps/web/components/apps/hitpay/HitpayPaymentComponent.tsx` → `onClose`
- `packages/app-store/hitpay/api/callback.ts` → `handler`
- `packages/app-store/hitpay/lib/PaymentService.ts` → `create`
- `packages/app-store/zoho-bigin/api/callback.ts` → `handler`
- `packages/app-store/zoho-bigin/lib/CrmService.ts` → `(anonymous)`
- `packages/app-store/zohocrm/api/callback.ts` → `handler`
- `packages/app-store/zohocrm/lib/CrmService.ts` → `(anonymous)`
Existing test(s) that load `qs` but don't reach the functions above — **extend these**: `packages/app-store/hitpay/lib/PaymentService.test.ts`.
Currently-unexercised functions in `qs` (context only — chainstrip removes these; do NOT write tests to reach them): `RFC1738`, `arrayToObject`, `assert`, `assignSingleSource`, `bind`, `brackets`, `combine`, `compact`, `compactQueue`, `concatty`, `decode`, `delete` … (+38 more).

### 5. ⚠ `cookie` — CLASSIFY 2KB — 2KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)  ⚠ 1 live CVE (LOW)
Runner evidence: `packages/trpc/server/routers/viewer/slots/reserveSlot.handler.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (5 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/trpc/server/routers/viewer/slots/reserveSlot.handler.ts` → `reserveSlotHandler`
Existing test(s) that load `cookie` but don't reach the functions above — **extend these**: `packages/trpc/server/routers/viewer/slots/reserveSlot.handler.test.ts`.
Currently-unexercised functions in `cookie` (context only — chainstrip removes these; do NOT write tests to reach them): `decode`, `endIndex`, `parse`, `startIndex`, `tryDecode`.

### 6. ⚠ `dompurify` — CLASSIFY 1KB — 1KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)  ⚠ 13 live CVEs (MODERATE)
Runner evidence: `packages/platform/atoms/lib/markdownToSafeHTML.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/purify.es.mjs (8 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/lib/markdownToSafeHTMLClient.ts` → `markdownToSafeHTMLClient`
- `packages/platform/atoms/lib/markdownToSafeHTML.ts` → `markdownToSafeHTML`
Existing test(s) that load `dompurify` but don't reach the functions above — **extend these**: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `packages/platform/atoms/lib/markdownToSafeHTML.test.ts`.
Currently-unexercised functions in `dompurify` (context only — chainstrip removes these; do NOT write tests to reach them): `DOMPurify`, `_sanitizeShadowDOM`, `addHook`, `apply`, `cleanArray`, `clearConfig`, `construct`, `createHTML`, `createScriptURL`, `fallbackValue`, `freeze`, `isRegexOrFunction` … (+5 more).

### 7. `jimp` — CLASSIFY 685KB — 685KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/lib/server/PiiHasher.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (1047 fns, 685KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 0 witnessed, 7 unreached — stated reasons: "Skipping `fn:jimp/dist/index.js@1130617` (`write`, sax-style XML parser): this path is exercised by jimp's bitmap-font/XMP-loading plugins, not by the simple `jimp.read()`/`resize()` flow in `resizeBase64Image.ts`, so it isn't reachable through the listed app call path without constructing an out-of-contract fixture (a font XML descriptor) that this call path never consumes.". (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/lib/server/resizeBase64Image.ts` → `resizeBase64Image`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `jimp` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `packages/lib/server/PiiHasher.test.ts`, `packages/lib/server/avatar.test.ts`, `packages/lib/server/defaultHandler.test.ts`, `packages/lib/server/defaultResponder.test.ts`, `packages/lib/server/getServerErrorFromUnknown.test.ts` … (+2 more).
Currently-unexercised functions in `jimp` (context only — chainstrip removes these; do NOT write tests to reach them): `AbstractDistanceCalculator`, `AbstractEuclidean`, `AbstractImageQuantizer`, `AbstractManhattan`, `AbstractPaletteQuantizer`, `AsyncIterator`, `BmpDecoder`, `BmpEncoder`, `Builder`, `CIE94GraphicArts`, `CIE94Textiles`, `CIEDE2000` … (+972 more).

### 8. `svix` — CLASSIFY 447KB — 447KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/BookingPageTagManager.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (485 fns, 447KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/alby/lib/parseInvoice.ts` → `parseInvoice`
Currently-unexercised functions in `svix` (context only — chainstrip removes these; do NOT write tests to reach them): `HMAC`, `Hash`, `Url`, `_decodeChar`, `_encodeByte`, `_getPaddingLength`, `_restoreState`, `_saveState`, `addCookie`, `agent`, `appPortalAccess`, `applySecurityAuthentication` … (+171 more).

### 9. `lexical` — CLASSIFY 361KB — 361KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/ui/components/editor/nodes/VariableNode.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `Lexical.js (110 fns, 361KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 1 witnessed, 0 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/editor/nodes/VariableNode.ts` → `$createVariableNode`
- `packages/ui/components/editor/plugins/AddVariablesPlugin.tsx` → `(anonymous)`
- `packages/ui/components/editor/plugins/customEnterKeyPlugin.tsx` → `(anonymous)`
- `packages/ui/components/editor/plugins/PlainTextPlugin.tsx` → `(anonymous)`
- `packages/ui/components/editor/plugins/ToolbarPlugin.tsx` → `(anonymous)`, `onClick`
Existing test(s) that load `lexical` but don't reach the functions above — **extend these**: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `packages/ui/components/editor/Editor.test.tsx`, `packages/ui/components/editor/nodes/VariableNode.test.ts`, `packages/ui/components/editor/plugins/CustomEnterKeyPlugin.test.tsx`, `packages/ui/components/editor/plugins/ToolbarPlugin.test.tsx`.
Currently-unexercised functions in `lexical` (context only — chainstrip removes these; do NOT write tests to reach them): `$addUpdateTag`, `$b`, `$createRangeSelection`, `$getTextContent`, `$isInlineElementOrDecoratorNode`, `$nodesOfType`, `$parseSerializedNode`, `Ac`, `DEPRECATED_$createGridSelection`, `Dc`, `Ee`, `Fe` … (+156 more).

### 10. `libphonenumber-js` — CLASSIFY 318KB — 318KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `chainstrip-chunk-M1TV2Ncb.cjs (371 fns, 193KB)`, `chainstrip-chunk-Dak9lXDw.mjs (283 fns, 124KB)`, `max/index.js (9 fns, 0KB)`, `max/index.cjs (7 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/dialog/EditLocationDialog.tsx` → `(anonymous)`
- `apps/web/components/phone-input/PhoneInput.tsx` → `refactorMeWithoutEffect`
- `apps/web/modules/event-types/components/CreateEventTypeDialog.tsx` → `(anonymous)`
- `packages/app-store/locations.ts` → `(anonymous)`
- `packages/features/bookings/lib/getBookingResponsesSchema.ts` → `(anonymous)`
- `packages/features/bookings/lib/handleNewBooking/handleCustomInputs.ts` → `(anonymous)`
- `packages/lib/formatPhoneNumber.ts` → `formatPhoneNumber`
Existing test(s) that load `libphonenumber-js` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/components/phone-input/PhoneInput.test.ts`, `apps/web/lib/daily-webhook/tests/recorded-daily-video.test.ts` … (+59 more).
Currently-unexercised functions in `libphonenumber-js` (context only — chainstrip removes these; do NOT write tests to reach them): `AsYouType`, `AsYouTypeFormatter`, `AsYouTypeParser`, `AsYouTypeState`, `CREATE_CHARACTER_CLASS_PATTERN`, `CREATE_STANDALONE_DIGIT_PATTERN`, `EXACT_GROUPING`, `Format`, `IDDPrefix`, `LRUCache`, `Metadata`, `Node` … (+347 more).

### 11. `date-fns` — CLASSIFY 310KB — 310KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/data-table/components/filters/ColumnVisibilityButton.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (246 fns, 91KB)`, `index.mjs (237 fns, 83KB)`, `locale.js (280 fns, 79KB)`, `chainstrip-chunk-CDMzOmCM.cjs (53 fns, 20KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/blocklist/components/BlocklistEntryDetailsSheet.tsx` → `(anonymous)`
- `apps/web/modules/booking-audit/components/BookingHistory.tsx` → `(anonymous)`
- `apps/web/modules/data-table/components/filters/DateRangeFilter.tsx` → `DateRangeFilter`
- `packages/ui/components/form/date-range-picker/DateRangePicker.tsx` → `(anonymous)`, `DatePickerWithRange`
- `packages/ui/components/form/datepicker/DatePicker.tsx` → `DatePicker`
Existing test(s) that load `date-fns` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+22 more).
Currently-unexercised functions in `date-fns` (context only — chainstrip removes these; do NOT write tests to reach them): `B`, `D`, `E`, `G`, `H`, `I`, `K`, `L`, `M`, `O`, `Q`, `R` … (+573 more).

### 12. `google-auth-library` — CLASSIFY 286KB — 286KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `build/src/index.js (432 fns, 286KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.ts` → `getUsersFromGWorkspace`
Existing test(s) that load `google-auth-library` but don't reach the functions above — **extend these**: `packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.test.ts`.
Currently-unexercised functions in `google-auth-library` (context only — chainstrip removes these; do NOT write tests to reach them): `DataStream`, `O`, `RETRY_CONFIG`, `SafeBuffer`, `SignStream`, `VerifyStream`, `_BaseExternalAccountClient_internalRefreshAccessTokenAsync`, `_DefaultAwsSecurityCredentialsSupplier_getAwsRoleName`, `_DefaultAwsSecurityCredentialsSupplier_getImdsV2SessionToken`, `_DefaultAwsSecurityCredentialsSupplier_regionFromEnv_get`, `_DefaultAwsSecurityCredentialsSupplier_retrieveAwsSecurityCredentials`, `_DefaultAwsSecurityCredentialsSupplier_securityCredentialsFromEnv_get` … (+344 more).

### 13. `@radix-ui/react-dropdown-menu` — CLASSIFY 219KB — 219KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/button/button.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (320 fns, 219KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/button/SplitButton.tsx` → `(anonymous)`, `SplitButton2`
- `packages/ui/components/dropdown/Dropdown.tsx` → `(anonymous)`, `DropdownMenuLabel`
Existing test(s) that load `@radix-ui/react-dropdown-menu` but don't reach the functions above — **extend these**: `apps/web/components/apps/InstallAppButtonChild.test.tsx`, `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx` … (+16 more).
Currently-unexercised functions in `@radix-ui/react-dropdown-menu` (context only — chainstrip removes these; do NOT write tests to reach them): `$3db38b7d1fb3fe6a$export$b7ece24a22aeda8c`, `$3db38b7d1fb3fe6a$var$createFocusGuard`, `$5cb92bef7577960e$var$dispatchUpdate`, `$5cb92bef7577960e$var$handleAndDispatchCustomEvent`, `$5cb92bef7577960e$var$useFocusOutside`, `$5cb92bef7577960e$var$usePointerDownOutside`, `$6cc32821e9371a1c$export$71bdb9d1e2909932`, `$6cc32821e9371a1c$export$793392f970497feb`, `$6cc32821e9371a1c$var$focusFirst`, `$6cc32821e9371a1c$var$getCheckedState`, `$6cc32821e9371a1c$var$getNextMatch`, `$6cc32821e9371a1c$var$getOpenState` … (+199 more).

### 14. `framer-motion` — CLASSIFY 215KB — 215KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/es/index.mjs (416 fns, 215KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/auth/verify-view.tsx` → `PaymentSuccess`
- `apps/web/modules/bookings/components/AvailableTimes.tsx` → `SlotItem`
- `apps/web/modules/bookings/components/Booker.tsx` → `Booker`, `BookerComponent`
- `apps/web/modules/bookings/components/EventMeta.tsx` → `EventMeta`
- `apps/web/modules/onboarding/components/onboarding-browser-view.tsx` → `OnboardingBrowserView`
- `apps/web/modules/onboarding/components/onboarding-calendar-browser-view.tsx` → `OnboardingCalendarBrowserView`
- `apps/web/modules/onboarding/components/onboarding-invite-browser-view.tsx` → `OnboardingInviteBrowserView`
- `apps/web/modules/onboarding/components/onboarding-migrate-members-browser-view.tsx` → `OnboardingMigrateMembersBrowserView`
- `apps/web/modules/onboarding/components/onboarding-organization-browser-view.tsx` → `OnboardingOrganizationBrowserView`
- `apps/web/modules/onboarding/components/OnboardingCard.tsx` → `OnboardingCard`
- `apps/web/modules/onboarding/components/plan-icon.tsx` → `PlanIcon`, `renderSmallUserIcon`
- `apps/web/modules/onboarding/getting-started/onboarding-view.tsx` → `OnboardingView`
- `packages/features/bookings/Booker/config.ts` → `(anonymous)`, `useBookerResizeAnimation`
- `packages/features/bookings/components/Section.tsx` → `BookerSection2`
Existing test(s) that load `framer-motion` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/components/Booker.test.tsx`.
Currently-unexercised functions in `framer-motion` (context only — chainstrip removes these; do NOT write tests to reach them): `AnimateSharedLayout`, `LayoutGroup`, `MeasureLayout`, `MotionConfig`, `PopChild`, `ReorderGroup`, `ReorderItem`, `add`, `addDomEvent`, `addEventListener`, `addHoverEvent`, `addKeyframes` … (+425 more).

### 15. `@googleapis/admin` — CLASSIFY 174KB — 174KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `build/index.js (149 fns, 174KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.ts` → `getUsersFromGWorkspace`
Existing test(s) that load `@googleapis/admin` but don't reach the functions above — **extend these**: `packages/trpc/server/routers/viewer/googleWorkspace/googleWorkspace.handler.test.ts`.
Currently-unexercised functions in `@googleapis/admin` (context only — chainstrip removes these; do NOT write tests to reach them): `action`, `admin`, `batchChangeStatus`, `batchCreatePrintServers`, `batchCreatePrinters`, `batchDeletePrintServers`, `batchDeletePrinters`, `constructor`, `create`, `delete`, `generate`, `get` … (+16 more).

### 16. `@daily-co/daily-js` — CLASSIFY 171KB — 171KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/videos/__tests__/cal-video-premium-features.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/daily.js (585 fns, 171KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/videos/views/videos-single-view.tsx` → `(anonymous)`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `@daily-co/daily-js` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `apps/web/modules/videos/__tests__/cal-video-premium-features.test.tsx`.
Currently-unexercised functions in `@daily-co/daily-js` (context only — chainstrip removes these; do NOT write tests to reach them): `$`, `$e`, `$n`, `$o`, `A`, `Ae`, `An`, `As`, `B`, `Be`, `Bn`, `Bo` … (+461 more).

### 17. `jose` — CLASSIFY 170KB — 170KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/auth/lib/getServerSession.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/node/esm/index.js (159 fns, 87KB)`, `dist/node/cjs/index.js (165 fns, 82KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/server/lib/auth/login/getServerSideProps.tsx` → `verifyJwt`
- `packages/features/auth/lib/signJwt.ts` → `signJwt`
Existing test(s) that load `jose` but don't reach the functions above — **extend these**: `packages/features/auth/lib/signJwt.test.ts`.
Currently-unexercised functions in `jose` (context only — chainstrip removes these; do NOT write tests to reach them): `EmbeddedJWK`, `add`, `addRecipient`, `addSignature`, `asymmetricTypeCheck`, `bitLength`, `bitLength$1`, `bitStr`, `calculateJwkThumbprint`, `calculateJwkThumbprintUri`, `cbcDecrypt`, `cbcEncrypt` … (+145 more).

### 18. `@radix-ui/react-hover-card` — CLASSIFY 141KB — 141KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (198 fns, 141KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/bookings/components/AvailableTimes.tsx` → `SlotItem`
- `packages/ui/components/hover-card/index.tsx` → `(anonymous)`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `@radix-ui/react-hover-card` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx`, `apps/web/modules/bookings/components/DatePicker.test.tsx`.
Currently-unexercised functions in `@radix-ui/react-hover-card` (context only — chainstrip removes these; do NOT write tests to reach them): `$5cb92bef7577960e$var$dispatchUpdate`, `$5cb92bef7577960e$var$handleAndDispatchCustomEvent`, `$5cb92bef7577960e$var$useFocusOutside`, `$5cb92bef7577960e$var$usePointerDownOutside`, `$6ed0406888f73fc4$export$43e446d32b3d21af`, `$6ed0406888f73fc4$export$c7b2cbe3552a0d05`, `$6ed0406888f73fc4$var$setRef`, `$71cd76cc60e0454e$export$6f32135080cb4c3`, `$71cd76cc60e0454e$var$useUncontrolledState`, `$8927f6f2acc4f386$export$6d1a0317bde7de7f`, `$921a889cee6df7e8$export$99c2b779aa4e8b8b`, `$921a889cee6df7e8$var$usePresence` … (+132 more).

### 19. `next-seo` — UNLOCK ≤140KB — its extraction already ships on BUILD evidence only (no test). A test upgrades the evidence AND lets covtrim stub its dead functions — up to ~140KB, unmeasured until a test loads it.
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/components/phone-input/PhoneInput.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Witness probes so far: 0 witnessed, 1 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/PageWrapper.tsx` → `PageWrapper`

### 20. `ical.js` — CLASSIFY 139KB — 139KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/BookingPageTagManager.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `build/ical.js (270 fns, 139KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/ics-feedcalendar/lib/CalendarService.ts` → `(anonymous)`
- `packages/lib/CalendarService.ts` → `(anonymous)`
Existing test(s) that load `ical.js` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `packages/features/availability/lib/calculateHolidayBlockedDates.test.ts`, `packages/features/bookings/lib/EventManager.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/buildDryRunBooking.test.ts` … (+4 more).
Currently-unexercised functions in `ical.js` (context only — chainstrip removes these; do NOT write tests to reach them): `BYDAY`, `Binary`, `COUNT`, `Component`, `ComponentParser`, `Event`, `FREQ`, `INTERVAL`, `ParserError`, `Property`, `RecurExpansion`, `UNTIL` … (+233 more).

### 21. `lodash` — CLASSIFY 132KB — 132KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/modules/data-table/components/filters/ColumnVisibilityButton.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lodash.js (413 fns, 111KB)`, `chainstrip-chunk-D0uk3-ZQ.cjs (6 fns, 7KB)`, `chainstrip-chunk-BJqxCX9F.cjs (4 fns, 3KB)`, `chainstrip-chunk-dFUbOQz-.cjs (9 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/ui/UsernameAvailability/PremiumTextfield.tsx` → `PremiumTextfield`
- `apps/web/components/ui/UsernameAvailability/UsernameTextfield.tsx` → `UsernameTextfield`
- `apps/web/modules/apps/components/AdminAppsList.tsx` → `AdminAppsList`
- `apps/web/modules/auth/forgot-password/forgot-password-view.tsx` → `ForgotPassword`
- `apps/web/modules/data-table/components/DataTable.tsx` → `(anonymous)`
- `apps/web/modules/data-table/components/DataTableWrapper.tsx` → `DataTableWrapper`
- `apps/web/modules/data-table/components/filters/AddFilterButton.tsx` → `(anonymous)`
- `apps/web/modules/data-table/components/filters/FilterPopover.tsx` → `FilterPopover`
- `apps/web/modules/data-table/contexts/DataTableFiltersContext.tsx` → `(anonymous)`
- `apps/web/modules/data-table/hooks/useColumnResizing.ts` → `(anonymous)`
- `apps/web/modules/data-table/hooks/useColumnSizingVars.ts` → `(anonymous)`
- `apps/web/modules/data-table/hooks/useDebouncedWidth.ts` → `(anonymous)`
- `apps/web/modules/data-table/hooks/useSegmentsNoop.ts` → `useSegmentsNoop`
- `apps/web/modules/settings/my-account/profile-view.tsx` → `(anonymous)`
- `apps/web/modules/users/components/UserForm.tsx` → `UserForm`
- `packages/emails/email-manager.ts` → `sendCancelledSeatEmailsAndSMS`, `sendRescheduledSeatEmailAndSMS`
- `packages/emails/templates/attendee-scheduled-email.ts` → `constructor`, `getNodeMailerPayload`
- `packages/emails/templates/organizer-scheduled-email.ts` → `getNodeMailerPayload`
- `packages/features/bookings/lib/BookingEmailSmsHandler.ts` → `_handleRoundRobinRescheduled`
- `packages/features/bookings/lib/EventManager.ts` → `create`, `processLocation`, `reschedule`
- `packages/features/bookings/lib/handleSeats/create/createNewSeat.ts` → `createNewSeat`
- `packages/features/bookings/lib/handleSeats/reschedule/attendee/attendeeRescheduleSeatedBooking.ts` → `attendeeRescheduleSeatedBooking`
- `packages/features/bookings/lib/handleSeats/reschedule/owner/combineTwoSeatedBookings.ts` → `combineTwoSeatedBookings`
- `packages/features/bookings/lib/handleSeats/reschedule/owner/moveSeatedBookingToNewTimeSlot.ts` → `moveSeatedBookingToNewTimeSlot`
- `packages/features/calendars/lib/CalendarManager.ts` → `(anonymous)`
- `packages/features/eventtypes/lib/getEventTypesByViewer.ts` → `getEventTypesByViewer`
- `packages/lib/formatCalendarEvent.ts` → `formatCalEvent`
- `packages/platform/atoms/booker/BookerPlatformWrapper.tsx` → `(anonymous)`
- `packages/trpc/server/routers/viewer/me/updateProfile.handler.ts` → `updateProfileHandler`
Existing test(s) that load `lodash` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `apps/web/lib/daily-webhook/tests/recorded-daily-video.test.ts`, `apps/web/modules/schedules/components/date-override-list.test.tsx`, `apps/web/pages/api/book/recurring-event.test.ts` … (+44 more).
Currently-unexercised functions in `lodash` (context only — chainstrip removes these; do NOT write tests to reach them): `LazyWrapper`, `LodashWrapper`, `SetCache`, `after`, `arrayAggregator`, `arrayEachRight`, `arrayEvery`, `arrayIncludes`, `arrayIncludesWith`, `arrayMap`, `arrayReduce`, `arrayReduceRight` … (+377 more).

### 22. `@radix-ui/react-tooltip` — CLASSIFY 130KB — 130KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/avatar/UserAvatar.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (185 fns, 130KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/lib/app-providers-app-dir.tsx` → `AppProviders`
- `apps/web/lib/app-providers.tsx` → `AppProviders`
- `packages/platform/atoms/cal-provider/BaseCalProvider.tsx` → `BaseCalProvider`
- `packages/ui/components/avatar/Avatar.tsx` → `Avatar`
- `packages/ui/components/tooltip/Tooltip.tsx` → `Tooltip`
Existing test(s) that load `@radix-ui/react-tooltip` but don't reach the functions above — **extend these**: `apps/web/components/apps/InstallAppButtonChild.test.tsx`, `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx` … (+24 more).
Currently-unexercised functions in `@radix-ui/react-tooltip` (context only — chainstrip removes these; do NOT write tests to reach them): `$5cb92bef7577960e$var$dispatchUpdate`, `$5cb92bef7577960e$var$handleAndDispatchCustomEvent`, `$5cb92bef7577960e$var$useFocusOutside`, `$5cb92bef7577960e$var$usePointerDownOutside`, `$8927f6f2acc4f386$export$6d1a0317bde7de7f`, `$a093c7e1ec25a057$var$getExitSideFromRect`, `$a093c7e1ec25a057$var$getHull`, `$a093c7e1ec25a057$var$getHullPresorted`, `$a093c7e1ec25a057$var$getPaddedExitPoints`, `$a093c7e1ec25a057$var$getPointsFromRect`, `$a093c7e1ec25a057$var$isPointInPolygon`, `$addc16e1bbe58fd0$export$3a72a57244d6e765` … (+123 more).

### 23. `zod` — CLASSIFY 123KB — 123KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/app/api/social/og/image/__tests__/route.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.cjs (198 fns, 93KB)`, `index.js (121 fns, 30KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 0 witnessed, 1 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/app/api/social/og/image/route.tsx` → `handler`
- `apps/web/app/api/verify-booking-token/route.ts` → `postHandler`
- `apps/web/components/apps/btcpayserver/Setup.tsx` → `BTCPaySetupPage`
- `apps/web/components/apps/hitpay/Setup.tsx` → `HitPaySetupPage`
- `apps/web/components/apps/installation/ConfigureStepCard.tsx` → `EventTypeAppSettingsForm2`
- `apps/web/components/dialog/AddGuestsDialog.tsx` → `AddGuestsDialog`
- `apps/web/components/dialog/EditLocationDialog.tsx` → `(anonymous)`, `EditLocationDialog`
- `apps/web/components/dialog/ReassignDialog.tsx` → `onValueChange`
- `apps/web/components/getting-started/steps-views/UserSettings.tsx` → `UserSettings`
- `apps/web/components/settings/SecondaryEmailModal.tsx` → `SecondaryEmailModal`
- `apps/web/components/setup/AdminUser.tsx` → `(anonymous)`, `AdminUser`
- `apps/web/lib/apps/installation/[[...step]]/getServerSideProps.ts` → `getInstallationParams`, `getServerSideProps`
- `apps/web/lib/getThemeProviderProps.ts` → `getThemeProviderProps`
- `apps/web/lib/signup/getServerSideProps.tsx` → `getServerSideProps`
- `apps/web/modules/auth/login-view.tsx` → `Login`
- `apps/web/modules/event-types/components/EventTypeWebWrapper.tsx` → `EventTypeWeb`
- `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.tsx` → `onChange`
- `apps/web/modules/onboarding/personal/settings/personal-settings-view.tsx` → `PersonalSettingsView`
- `apps/web/modules/settings/my-account/profile-view.tsx` → `ProfileForm`
- `apps/web/modules/webhooks/components/WebhookTestDisclosure.tsx` → `onClick`
- `packages/app-store/_utils/oauth/parseRefreshTokenResponse.ts` → `(anonymous)`
- `packages/app-store/dailyvideo/lib/VideoApiAdapter.ts` → `(anonymous)`
- `packages/app-store/giphy/api/get.ts` → `(anonymous)`
- `packages/app-store/giphy/api/search.ts` → `(anonymous)`
- `packages/app-store/locations.ts` → `(anonymous)`, `getTranslatedLocation`, `locationsResolver`
- `packages/app-store/stripepayment/api/add.ts` → `handler`
- `packages/app-store/stripepayment/pages/setup/_getServerSideProps.ts` → `getServerSideProps`
- `packages/app-store/vital/api/save.ts` → `(anonymous)`
- `packages/app-store/wipemycalother/api/wipe.ts` → `(anonymous)`
- `packages/emails/templates/_base-email.ts` → `sendEmail`
- `packages/features/apps/components/AppSetDefaultLinkDialog.tsx` → `AppSetDefaultLinkDialog`
- `packages/features/booking-audit/lib/actions/AuditActionServiceHelper.ts` → `getVersion`
- `packages/features/bookings/Booker/hooks/useBookingForm.ts` → `useBookingForm`
- `packages/features/bookings/lib/getBookingDataSchema.ts` → `getBookingDataSchema`
- `packages/features/bookings/lib/getBookingDataSchemaForApi.ts` → `getBookingDataSchemaForApi`
- `packages/features/bookings/lib/getBookingResponsesSchema.ts` → `(anonymous)`, `getBookingResponsesSchema`, `getBookingResponsesSchemaWithOptionalChecks`, `preprocess`, `superRefineField`
- `packages/features/bookings/lib/handleNewBooking/handleCustomInputs.ts` → `validateBooleanInput`, `validatePhoneInput`, `validateStringInput`
- `packages/features/form-builder/schema.ts` → `(anonymous)`, `nonEmptyString`, `preprocess`, `superRefine`
- `packages/lib/apps/getInstallCountPerApp.ts` → `computeInstallCountsFromDB`
- `packages/lib/domainManager/deploymentServices/cloudflare.ts` → `getDnsRecordToDelete`
- `packages/lib/getAvatarUrl.ts` → `getAbsoluteAvatarUrl`
- `packages/lib/hooks/useTypedQuery.ts` → `(anonymous)`
- `packages/lib/server/getServerErrorFromUnknown.ts` → `isZodError`
- `packages/platform/atoms/event-types/hooks/useEventTypeForm.ts` → `(anonymous)`, `useEventTypeForm`
- `packages/prisma/zod-utils.ts` → `(anonymous)`, `denullish`, `denullishShape`, `getStringAsNumberRequiredSchema`, `optionToValueSchema`
- `packages/prisma/zod/inputTypeSchemas/InputJsonValueSchema.ts` → `(anonymous)`
- `packages/prisma/zod/inputTypeSchemas/JsonValueSchema.ts` → `(anonymous)`
- `packages/trpc/server/errorFormatter.ts` → `errorFormatter`
- `packages/trpc/server/procedures/pbacProcedures.ts` → `createTeamPbacProcedure`
- `packages/trpc/server/routers/viewer/admin/createCoupon.handler.ts` → `createCoupon`
- `packages/trpc/server/routers/viewer/admin/createSelfHostedLicenseKey.handler.ts` → `createSelfHostedInstance`
- `packages/trpc/server/routers/viewer/apps/updateUserDefaultConferencingApp.handler.ts` → `updateUserDefaultConferencingAppHandler`
- `packages/trpc/server/routers/viewer/eventTypes/util.ts` → `createEventPbacProcedure`
- `packages/trpc/server/routers/viewer/oAuth/updateClient.schema.ts` → `(anonymous)`
Existing test(s) that load `zod` but don't reach the functions above — **extend these**: `apps/web/app/api/auth/oauth/token/__tests__/route.test.ts`, `apps/web/app/api/auth/signup/handlers/calcomSignupHandler.test.ts`, `apps/web/app/api/auth/signup/handlers/selfHostedHandler.test.ts`, `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/cron/selected-calendars/__tests__/cron.test.ts` … (+175 more).
Currently-unexercised functions in `zod` (context only — chainstrip removes these; do NOT write tests to reach them): `BRAND`, `DIRTY`, `EMPTY_PATH`, `Enum`, `INVALID`, `NEVER`, `OK`, `ParseStatus`, `Schema`, `Values`, `ZodAny`, `ZodArray` … (+256 more).

### 24. `react-easy-crop` — UNLOCK ≤110KB — its extraction already ships on BUILD evidence only (no test). A test upgrades the evidence AND lets covtrim stub its dead functions — up to ~110KB, unmeasured until a test loads it.
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/TokenHandler/token-handler.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Witness probes so far: 0 witnessed, 1 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/image-uploader/BannerUploader.tsx` → `CropContainer`
- `packages/ui/components/image-uploader/ImageUploader.tsx` → `CropContainer`

### 25. `rrule` — CLASSIFY 108KB — 108KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/googlecalendar/lib/__tests__/CalendarService.auth.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/esm/index.js (175 fns, 88KB)`, `dist/es5/rrule.js (68 fns, 20KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 0 witnessed, 1 unreached — stated reasons: "Skipping `fn:rrule/dist/esm/index.js@34474` (`parseText`) — every listed call path only does `new RRule(options).toString()` (constructor + serialization), never `RRule.fromText`/natural-language parsing; that code path is not exercised by any of the given app usages.". (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/googlecalendar/lib/CalendarService.ts` → `createEvent`
- `packages/app-store/salesforce/lib/CrmService.ts` → `(anonymous)`
- `packages/emails/lib/generateIcsString.ts` → `generateIcsString`
- `packages/emails/src/components/WhenInfo.tsx` → `getRecurringWhen`
- `packages/features/bookings/lib/getCalendarLinks.ts` → `buildGoogleCalendarLink`
- `packages/lib/parse-dates.ts` → `parseRecurringDates`
Existing test(s) that load `rrule` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `apps/web/lib/daily-webhook/tests/recorded-daily-video.test.ts`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/pages/api/book/recurring-event.test.ts` … (+51 more).
Currently-unexercised functions in `rrule` (context only — chainstrip removes these; do NOT write tests to reach them): `AT`, `At`, `Cache`, `CallbackIterResult`, `DAILY`, `DateTime`, `DateWithZone`, `F`, `Frequency`, `H`, `HOURLY`, `IterResult` … (+190 more).

### 26. `i18next` — CLASSIFY 97KB — 97KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/app/WithEmbedSSR.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/cjs/i18next.js (114 fns, 70KB)`, `dist/esm/i18next.js (93 fns, 27KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/app/layout.tsx` → `getInitialProps`
- `apps/web/lib/app-providers.tsx` → `(anonymous)`
- `apps/web/pages/_document.tsx` → `render`
- `packages/i18n/server.ts` → `getTranslation`
- `packages/lib/hooks/useLocale.ts` → `useLocale`
Existing test(s) that load `i18next` but don't reach the functions above — **extend these**: `apps/web/app/api/auth/signup/handlers/calcomSignupHandler.test.ts`, `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx` … (+47 more).
Currently-unexercised functions in `i18next` (context only — chainstrip removes these; do NOT write tests to reach them): `1`, `10`, `11`, `12`, `13`, `14`, `15`, `16`, `17`, `18`, `19`, `2` … (+117 more).

### 27. `react-day-picker` — CLASSIFY 97KB — 97KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/form/date-range-picker/dateRangeLogic.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.esm.js (127 fns, 70KB)`, `dist/index.js (42 fns, 27KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/form/date-range-picker/Calendar.tsx` → `Calendar`
Existing test(s) that load `react-day-picker` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+7 more).
Currently-unexercised functions in `react-day-picker` (context only — chainstrip removes these; do NOT write tests to reach them): `Caption`, `CaptionDropdowns`, `CaptionLabel`, `CaptionNavigation`, `Day`, `DayContent`, `DayPicker`, `DayPickerProvider`, `Dropdown`, `FocusProvider`, `Footer`, `Head` … (+124 more).

### 28. `@tanstack/react-table` — CLASSIFY 90KB — 90KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `build/lib/index.mjs (226 fns, 90KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/app/(use-page-wrapper)/settings/(admin-layout)/admin/playground/date-range-filter/page.tsx` → `ScenarioCard`
- `apps/web/modules/blocklist/components/BlockedEntriesTable.tsx` → `BlockedEntriesTable`
- `apps/web/modules/blocklist/components/PendingReportsTable.tsx` → `PendingReportsTable`
- `apps/web/modules/bookings/columns/filterColumns.ts` → `buildFilterColumns`
- `apps/web/modules/bookings/components/BookingCalendarContainer.tsx` → `BookingCalendarInner`
- `apps/web/modules/bookings/components/BookingListContainer.tsx` → `BookingListInner`
- `apps/web/modules/bookings/hooks/useBookingListColumns.tsx` → `(anonymous)`
- `apps/web/modules/data-table/components/DataTable.tsx` → `(anonymous)`, `TableHeadLabel`
- `apps/web/modules/settings/outOfOffice/OutOfOfficeEntriesList.tsx` → `(anonymous)`, `OutOfOfficeEntriesListContent`
- `apps/web/modules/users/components/UserTable/PlatformManagedUsersTable.tsx` → `UserListTableContent`
- `apps/web/modules/users/components/UserTable/UserListTable.tsx` → `UserListTableContent`
- `packages/features/schedules/components/DateOverrideList.tsx` → `DateOverrideList`
Existing test(s) that load `@tanstack/react-table` but don't reach the functions above — **extend these**: `apps/web/modules/data-table/components/filters/ColumnVisibilityButton.test.tsx`, `apps/web/modules/schedules/components/date-override-list.test.tsx`, `apps/web/modules/users/lib/UserListTableUtils.test.ts`.
Currently-unexercised functions in `@tanstack/react-table` (context only — chainstrip removes these; do NOT write tests to reach them): `_autoResetExpanded`, `_autoResetPageIndex`, `_getPinnedRows`, `_getRowId`, `_getVisibleLeafColumns`, `_queue`, `accessorFn`, `aggregatedCell`, `alphanumeric`, `alphanumericCaseSensitive`, `arrIncludes`, `arrIncludesAll` … (+182 more).

### 29. `react-qr-code` — UNLOCK ≤76KB — its extraction already ships on BUILD evidence only (no test). A test upgrades the evidence AND lets covtrim stub its dead functions — up to ~76KB, unmeasured until a test loads it.
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/components/apps/InstallAppButtonChild.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Witness probes so far: 1 witnessed, 0 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/apps/alby/AlbyPaymentComponent.tsx` → `AlbyPaymentComponent`

### 30. `googleapis-common` — CLASSIFY 74KB — 74KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/googlecalendar/lib/__tests__/CalendarService.auth.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `build/src/index.js (89 fns, 74KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 0 witnessed, 1 unreached — stated reasons: "Skipping `fn:googleapis-common/build/src/index.js@104270` (`createAPIRequestAsync`) — every listed call path only constructs an `OAuth2Client`/`JWT` (auth object creation), not an actual REST call; the one path that would issue a real API call (`updateProfilePhotoGoogle`) also touches Prisma/DB writes not safely stubbable here, so this can't be driven deterministically without deeper source access.". (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/googlecalendar/api/add.ts` → `getHandler`
- `packages/app-store/googlecalendar/api/callback.ts` → `getHandler`
- `packages/app-store/googlecalendar/lib/CalendarAuth.ts` → `getJwtClientSingleton`
- `packages/features/auth/lib/next-auth-options.ts` → `jwt`
Existing test(s) that load `googleapis-common` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `packages/app-store/googlecalendar/lib/__tests__/CalendarService.auth.test.ts`, `packages/app-store/googlecalendar/lib/__tests__/CalendarService.test.ts`, `packages/features/auth/lib/next-auth-options.test.ts` … (+7 more).
Currently-unexercised functions in `googleapis-common` (context only — chainstrip removes these; do NOT write tests to reach them): `O`, `_defaultAdapter`, `_getClient`, `_request`, `_transform`, `applyMethodsFromSchema`, `applySchema`, `buildurl`, `closeSession`, `coerce`, `connect`, `constructor` … (+79 more).

### 31. `kbar` — CLASSIFY 73KB — 73KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/shell/user-dropdown/UserDropdown.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lib/index.js (143 fns, 73KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/shell/Kbar.tsx` → `KBarContent`, `KBarRoot`, `KBarTrigger`, `RenderResults`, `useEventTypesAction`, `useUpcomingBookingsAction`
Currently-unexercised functions in `kbar` (context only — chainstrip removes these; do NOT write tests to reach them): `Escape`, `HistoryItemImpl`, `KBarAnimator$1`, `KBarResults$1`, `KBarSearch$1`, `Portal`, `_getNewCache`, `add`, `addChild`, `areArraysEqual`, `areMapsEqual`, `areObjectsEqual` … (+63 more).

### 32. `react-i18next` — CLASSIFY 61KB — 61KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/platform/atoms/lib/markdownToSafeHTML.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/commonjs/index.js (56 fns, 33KB)`, `dist/es/index.js (65 fns, 29KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/lib/hooks/useLocale.ts` → `useClientLocale`
- `packages/platform/atoms/lib/useLocale.ts` → `useLocale`
Existing test(s) that load `react-i18next` but don't reach the functions above — **extend these**: `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/bookings/components/DatePicker.test.tsx`, `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts`, `apps/web/modules/data-table/components/filters/ColumnVisibilityButton.test.tsx` … (+13 more).
Currently-unexercised functions in `react-i18next` (context only — chainstrip removes these; do NOT write tests to reach them): `I18nextProvider`, `I18nextProvider$1`, `ReportNamespaces`, `Trans`, `Trans$1`, `Translation`, `Translation$1`, `_arrayLikeToArray`, `_arrayWithHoles`, `_classCallCheck`, `_defineProperty`, `_iterableToArrayLimit` … (+70 more).

### 33. `@tanstack/react-virtual` — UNLOCK ≤61KB — its extraction already ships on BUILD evidence only (no test). A test upgrades the evidence AND lets covtrim stub its dead functions — up to ~61KB, unmeasured until a test loads it.
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/data-table/components/filters/ColumnVisibilityButton.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Witness probes so far: 0 witnessed, 1 unreached — stated reasons: "Skipping `dep:@tanstack/react-virtual`: the only listed call path (`DataTable.tsx`) pulls in sibling app modules (e.g. `~/data-table/hooks/useColumnResizing`) whose alias can't be resolved from the probe environment (confirmed by the prior failed attempt), and there is no second in-contract app path to `useVirtualizer` provided.". (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/data-table/components/DataTable.tsx` → `DataTable`, `DataTableBody`

### 34. `stripe` — CLASSIFY 54KB — 54KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/stripepayment/lib/VerificationTokenService.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lib/stripe.js (99 fns, 54KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/stripepayment/lib/PaymentService.ts` → `constructor`
Existing test(s) that load `stripe` but don't reach the functions above — **extend these**: `packages/app-store/stripepayment/api/__tests__/paymentCallback.test.ts`, `packages/app-store/stripepayment/api/__tests__/portal.test.ts`, `packages/app-store/stripepayment/lib/PaymentService.construction.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/fresh-booking.test.ts`.
Currently-unexercised functions in `stripe` (context only — chainstrip removes these; do NOT write tests to reach them): `_addHeadersDirectlyToObject`, `_defaultIdempotencyKey`, `_errorHandler`, `_generateConnectionErrorMessage`, `_getMaxNetworkRetries`, `_getRequestId`, `_getSleepTimeInMS`, `_getTelemetryHeader`, `_getUserAgentString`, `_joinUrlParts`, `_jsonResponseHandler`, `_makeHeaders` … (+93 more).

### 35. `@urql/core` — CLASSIFY 52KB — 52KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/salesforce/lib/graphql/__tests__/SalesforceGraphQLClient.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/urql-core.mjs (90 fns, 52KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/salesforce/lib/graphql/SalesforceGraphQLClient.ts` → `constructor`
Existing test(s) that load `@urql/core` but don't reach the functions above — **extend these**: `packages/app-store/salesforce/lib/__tests__/CrmService.integration.test.ts`, `packages/app-store/salesforce/lib/graphql/__tests__/SalesforceGraphQLClient.test.ts`, `packages/features/crmManager/crmManager.test.ts`.
Currently-unexercised functions in `@urql/core` (context only — chainstrip removes these; do NOT write tests to reach them): `Argument`, `BooleanValue`, `Client`, `Directive`, `Document`, `EnumValue`, `Field`, `FloatValue`, `FragmentDefinition`, `FragmentSpread`, `InlineFragment`, `IntValue` … (+110 more).

### 36. `@daily-co/daily-react` — CLASSIFY 49KB — 49KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/videos/__tests__/cal-video-premium-features.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (66 fns, 49KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/videos/cal-video-premium-features.tsx` → `CalVideoPremiumFeatures`
- `apps/web/modules/videos/views/videos-single-view.tsx` → `JoinCall`, `VideoMeetingInfo`
Existing test(s) that load `@daily-co/daily-react` but don't reach the functions above — **extend these**: `apps/web/modules/videos/__tests__/cal-video-premium-features.test.tsx`.
Currently-unexercised functions in `@daily-co/daily-react` (context only — chainstrip removes these; do NOT write tests to reach them): `$n`, `B`, `C`, `DailyProvider`, `Dn`, `E`, `Fn`, `Gn`, `I`, `J`, `K`, `Kn` … (+64 more).

### 37. `node-fetch` — CLASSIFY 47KB — 47KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/auth/signup/utils/getOrgUsernameFromEmail.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lib/index.js (126 fns, 47KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/auth/signup/utils/prefillAvatar.ts` → `downloadImageDataFromUrl`, `getImageUrlAvatarAPI`
Existing test(s) that load `node-fetch` but don't reach the functions above — **extend these**: `packages/features/auth/signup/utils/prefillAvatar.test.ts`.
Currently-unexercised functions in `node-fetch` (context only — chainstrip removes these; do NOT write tests to reach them): `AbortError`, `ByteString`, `DOMString`, `Date`, `FetchError`, `RegExp`, `URL`, `URLStateMachine`, `USVString`, `abort`, `abortAndFinalize`, `arrayBuffer` … (+131 more).

### 38. `@lexical/list` — CLASSIFY 45KB — 45KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/editor/plugins/AutoLinkPlugin.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `LexicalList.js (43 fns, 45KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 1 witnessed, 0 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/editor/plugins/customEnterKeyPlugin.tsx` → `(anonymous)`
- `packages/ui/components/editor/plugins/ToolbarPlugin.tsx` → `(anonymous)`, `formatBulletList`, `formatNumberedList`
Existing test(s) that load `@lexical/list` but don't reach the functions above — **extend these**: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `packages/ui/components/editor/Editor.test.tsx`, `packages/ui/components/editor/plugins/CustomEnterKeyPlugin.test.tsx`, `packages/ui/components/editor/plugins/ToolbarPlugin.test.tsx`.
Currently-unexercised functions in `@lexical/list` (context only — chainstrip removes these; do NOT write tests to reach them): `$handleListInsertParagraph`, `B`, `C`, `D`, `E`, `F`, `G`, `I`, `J`, `K`, `O`, `P` … (+49 more).

### 39. `@radix-ui/react-radio-group` — CLASSIFY 42KB — 42KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (69 fns, 42KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/event-types/components/tabs/advanced/DisableReschedulingController.tsx` → `render`
- `apps/web/modules/event-types/components/tabs/advanced/RequiresConfirmationController.tsx` → `render`
- `apps/web/modules/settings/components/BookerLayoutSelector.tsx` → `(anonymous)`, `BookerLayoutFields`
- `packages/app-store/stripepayment/components/EventTypeAppSettingsInterface.tsx` → `EventTypeAppSettingsInterface`
- `packages/features/eventtypes/components/tabs/limits/EventLimitsTab.tsx` → `RangeLimitRadioItem`, `RollingLimitRadioItem`, `render`
- `packages/ui/components/radio/Radio.tsx` → `Group`, `Indicator`, `Radio`
- `packages/ui/components/radio/RadioAreaGroup.tsx` → `RadioArea`, `RadioAreaGroup`
Existing test(s) that load `@radix-ui/react-radio-group` but don't reach the functions above — **extend these**: `apps/web/modules/form-builder/components/FormBuilderField.test.tsx`, `apps/web/modules/users/views/users-public-view.test.tsx`.
Currently-unexercised functions in `@radix-ui/react-radio-group` (context only — chainstrip removes these; do NOT write tests to reach them): `$010c2913dbd2fe3d$export$5cae361ad82dce8b`, `$6ed0406888f73fc4$export$43e446d32b3d21af`, `$6ed0406888f73fc4$export$c7b2cbe3552a0d05`, `$6ed0406888f73fc4$var$setRef`, `$71cd76cc60e0454e$export$6f32135080cb4c3`, `$71cd76cc60e0454e$var$useUncontrolledState`, `$921a889cee6df7e8$export$99c2b779aa4e8b8b`, `$921a889cee6df7e8$var$usePresence`, `$b1b2314f5f9a1d84$export$25bec8c6f54ee79a`, `$ce77a8961b41be9e$var$BubbleInput`, `$ce77a8961b41be9e$var$getState`, `$d7bdfb9eb0fdf311$var$getDirectionAwareKey` … (+18 more).

### 40. `react-timezone-select` — CLASSIFY 42KB — 42KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/features/CalendarEventBuilder.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/esm/index.js (242 fns, 42KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/timezone/components/TimezoneSelectComponent.tsx` → `TimezoneSelectComponent`
Existing test(s) that load `react-timezone-select` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/timezone/components/TimezoneSelect.test.tsx`.
Currently-unexercised functions in `react-timezone-select` (context only — chainstrip removes these; do NOT write tests to reach them): `$`, `$r`, `$t`, `A`, `An`, `Bo`, `Br`, `Ce`, `Control`, `Ct`, `D`, `DD` … (+328 more).

### 41. `@radix-ui/react-popover` — CLASSIFY 42KB — 42KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/form/color-picker/colorpicker.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (83 fns, 42KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/form/color-picker/colorpicker.tsx` → `ColorPicker`
- `packages/ui/components/form/date-range-picker/DateRangePicker.tsx` → `DatePickerWithRange`
- `packages/ui/components/form/datepicker/DatePicker.tsx` → `DatePicker`
- `packages/ui/components/popover/AnimatedPopover.tsx` → `AnimatedPopover`
- `packages/ui/components/popover/MeetingTimeInTimezones.tsx` → `MeetingTimeInTimezones`
- `packages/ui/components/popover/Popover.tsx` → `(anonymous)`
Existing test(s) that load `@radix-ui/react-popover` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/data-table/components/filters/ColumnVisibilityButton.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` … (+9 more).
Currently-unexercised functions in `@radix-ui/react-popover` (context only — chainstrip removes these; do NOT write tests to reach them): `$5cb92bef7577960e$var$handleAndDispatchCustomEvent`, `$8927f6f2acc4f386$export$6d1a0317bde7de7f`, `$cf1ac5d9fe0e8206$export$79d62cd4e10a3fd0`, `$cf1ac5d9fe0e8206$var$isNotNull`, `$d3863c46a17e8a28$var$findVisible`, `$d3863c46a17e8a28$var$getTabbableEdges`, `$d3863c46a17e8a28$var$isHidden`, `__spreadArray`, `alwaysContainsScroll`, `arrow`, `arrow$1`, `arrow$3` … (+56 more).

### 42. `@googleapis/calendar` — CLASSIFY 40KB — 40KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/googlecalendar/lib/__tests__/CalendarService.auth.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `build/index.js (35 fns, 40KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/googlecalendar/api/callback.ts` → `getHandler`
- `packages/app-store/googlecalendar/lib/CalendarAuth.ts` → `getClient`
- `packages/features/auth/lib/next-auth-options.ts` → `jwt`
Existing test(s) that load `@googleapis/calendar` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `packages/features/auth/lib/next-auth-options.test.ts`, `packages/features/availability/lib/calculateHolidayBlockedDates.test.ts`, `packages/features/bookings/lib/EventManager.test.ts` … (+5 more).
Currently-unexercised functions in `@googleapis/calendar` (context only — chainstrip removes these; do NOT write tests to reach them): `calendar`, `clear`, `constructor`, `delete`, `get`, `import`, `insert`, `instances`, `list`, `move`, `patch`, `query` … (+4 more).

### 43. `jsonwebtoken` — CLASSIFY 39KB — 39KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/auth/lib/getServerSession.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (70 fns, 39KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/auth/lib/oAuthAuthorization.ts` → `isAuthorized`
- `packages/features/oauth/services/OAuthService.ts` → `createTokens`, `verifyRefreshToken`
Existing test(s) that load `jsonwebtoken` but don't reach the functions above — **extend these**: `apps/web/app/api/auth/oauth/token/__tests__/route.test.ts`, `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `apps/web/pages/api/book/recurring-event.test.ts`, `apps/web/test/handlers/requestReschedule.test.ts` … (+25 more).
Currently-unexercised functions in `jsonwebtoken` (context only — chainstrip removes these; do NOT write tests to reach them): `DataStream`, `NotBeforeError`, `SafeBuffer`, `SignStream`, `TokenExpiredError`, `VerifyStream`, `alloc`, `allocUnsafe`, `allocUnsafeSlow`, `base64Url`, `checkIsPrivateKey`, `checkIsPublicKey` … (+70 more).

### 44. `async` — CLASSIFY 37KB — 37KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/bookings/lib/getAllCredentialsForUsersOnEvent/refreshCredentials.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/async.js (92 fns, 31KB)`, `forEach.js (25 fns, 6KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/bookings/lib/getAllCredentialsForUsersOnEvent/refreshCredentials.ts` → `_refreshCredentials`
Existing test(s) that load `async` but don't reach the functions above — **extend these**: `apps/web/pages/api/book/recurring-event.test.ts`, `packages/features/bookings/lib/getAllCredentialsForUsersOnEvent/refreshCredentials.test.ts`, `packages/features/bookings/lib/handleNewBooking/global-booking-limits.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/booking-flags.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/booking-limits.test.ts` … (+14 more).
Currently-unexercised functions in `async` (context only — chainstrip removes these; do NOT write tests to reach them): `_createTester`, `_filter`, `_withoutIndex`, `_withoutIndex3`, `apply`, `applyEach2`, `asyncEachOfLimit`, `asyncify`, `auto`, `autoInject`, `awaitable`, `cargo` … (+112 more).

### 45. `@lexical/selection` — CLASSIFY 36KB — 36KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/editor/plugins/AutoLinkPlugin.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `LexicalSelection.js (21 fns, 36KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 1 witnessed, 0 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/editor/plugins/ToolbarPlugin.tsx` → `(anonymous)`, `getSelectedNode`
Existing test(s) that load `@lexical/selection` but don't reach the functions above — **extend these**: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `packages/ui/components/editor/Editor.test.tsx`, `packages/ui/components/editor/plugins/ToolbarPlugin.test.tsx`.
Currently-unexercised functions in `@lexical/selection` (context only — chainstrip removes these; do NOT write tests to reach them): `$addNodeStyle`, `$cloneWithProperties`, `$getSelectionStyleValueForProperty`, `$isAtNodeEnd`, `$moveCharacter`, `$patchStyleText`, `$selectAll`, `$setBlocksType`, `$shouldOverrideDefaultCharacterSelection`, `$sliceSelectedTextNodeContent`, `A`, `B` … (+12 more).

### 46. `react-hook-form` — CLASSIFY 33KB — 33KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.cjs.js (34 fns, 21KB)`, `dist/index.esm.mjs (40 fns, 11KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 0 witnessed, 1 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/apps/applecalendar/Setup.tsx` → `AppleCalendarSetup`
- `apps/web/components/apps/btcpayserver/Setup.tsx` → `BTCPaySetupPage`
- `apps/web/components/apps/caldavcalendar/Setup.tsx` → `CalDavCalendarSetup`
- `apps/web/components/apps/exchange2013calendar/Setup.tsx` → `Exchange2013CalendarSetup`
- `apps/web/components/apps/exchange2016calendar/Setup.tsx` → `Exchange2016CalendarSetup`
- `apps/web/components/apps/exchangecalendar/Setup.tsx` → `ExchangeSetup`
- `apps/web/components/apps/hitpay/Setup.tsx` → `HitPaySetupPage`
- `apps/web/components/apps/ics-feedcalendar/Setup.tsx` → `ICSFeedSetup`
- `apps/web/components/apps/installation/ConfigureStepCard.tsx` → `ConfigureStepCardContent`, `EventTypeAppSettingsForm2`, `EventTypeGroup`
- `apps/web/components/apps/installation/EventTypeConferencingAppSettings.tsx` → `LocationsWrapper`
- `apps/web/components/apps/installation/EventTypesStepCard.tsx` → `EventTypeGroup`, `EventTypesStepCard`
- `apps/web/components/apps/sendgrid/Setup.tsx` → `SendgridSetup`
- `apps/web/components/auth/BackupCode.tsx` → `TwoFactor`
- `apps/web/components/auth/TwoFactor.tsx` → `TwoFactor`
- `apps/web/components/booking/BookingListItem.tsx` → `(anonymous)`, `GroupedAttendees`
- `apps/web/components/dialog/EditLocationDialog.tsx` → `EditLocationDialog`, `LocationInput`, `success`
- `apps/web/components/dialog/ReassignDialog.tsx` → `ReassignDialog`
- `apps/web/components/dialog/ReportBookingDialog.tsx` → `ReportBookingDialog`
- `apps/web/components/dialog/WrongAssignmentDialog.tsx` → `AdditionalNotesSection`, `AssigneeSection`, `WrongAssignmentDialog`
- `apps/web/components/getting-started/steps-views/SetupAvailability.tsx` → `SetupAvailability`
- `apps/web/components/getting-started/steps-views/UserProfile.tsx` → `UserProfile`
- `apps/web/components/getting-started/steps-views/UserSettings.tsx` → `UserSettings`
- `apps/web/components/security/DisableTwoFactorModal.tsx` → `DisableTwoFactorAuthModal`
- `apps/web/components/security/EnableTwoFactorModal.tsx` → `EnableTwoFactorModal`
- `apps/web/components/settings/DisableTwoFactorModal.tsx` → `DisableTwoFactorAuthModal`
- `apps/web/components/settings/EnableTwoFactorModal.tsx` → `EnableTwoFactorModal`
- `apps/web/components/settings/SecondaryEmailModal.tsx` → `SecondaryEmailModal`
- `apps/web/components/setup/AdminUser.tsx` → `AdminUser`
- `apps/web/components/ui/UsernameAvailability/index.tsx` → `UsernameAvailabilityField`
- `apps/web/modules/api-keys/api-keys/components/ApiKeyDialogForm.tsx` → `ApiKeyDialogForm`
- `apps/web/modules/apps/components/AdminAppsList.tsx` → `(anonymous)`, `EditKeysModal`
- `apps/web/modules/apps/installation/[[...step]]/step-view.tsx` → `OnboardingPage`
- `apps/web/modules/auth/forgot-password/[id]/forgot-password-single-view.tsx` → `Page`
- `apps/web/modules/auth/login-view.tsx` → `Login`
- `apps/web/modules/blocklist/components/BookingReportDetailsModal.tsx` → `BookingReportDetailsModal`
- `apps/web/modules/blocklist/components/CreateBlocklistEntryModal.tsx` → `CreateBlocklistEntryModal`
- `apps/web/modules/bookings/components/BookEventForm/BookingFields.tsx` → `BookingFields`
- `apps/web/modules/data-table/components/filters/NumberFilterOptions.tsx` → `NumberFilterOptions`
- `apps/web/modules/data-table/components/filters/TextFilterOptions.tsx` → `TextFilterOptions`
- `apps/web/modules/data-table/components/segment/DuplicateSegmentDialog.tsx` → `DuplicateSegmentDialog`
- `apps/web/modules/data-table/components/segment/RenameSegmentDialog.tsx` → `RenameSegmentDialog`
- `apps/web/modules/data-table/components/segment/SaveFilterSegmentButton.tsx` → `SaveFilterSegmentButton`
- `apps/web/modules/event-types/components/DuplicateDialog.tsx` → `DuplicateDialog`
- `apps/web/modules/event-types/components/locations/CalVideoSettings.tsx` → `CalVideoSettings`
- `apps/web/modules/event-types/components/locations/DefaultLocationSettings.tsx` → `DefaultLocationSettings`
- `apps/web/modules/event-types/components/locations/HostLocations.tsx` → `HostLocations`
- `apps/web/modules/event-types/components/locations/LocationInput.tsx` → `LocationInput`
- `apps/web/modules/event-types/components/locations/Locations.tsx` → `Locations`
- `apps/web/modules/event-types/components/MultiplePrivateLinksController.tsx` → `MultiplePrivateLinksController`
- `apps/web/modules/event-types/components/tabs/advanced/CustomEventTypeModal.tsx` → `CustomEventTypeModal`, `CustomEventTypeModalForm`
- `apps/web/modules/event-types/components/tabs/advanced/DisableReschedulingController.tsx` → `DisableReschedulingController`
- `apps/web/modules/event-types/components/tabs/advanced/EventAdvancedTab.tsx` → `CalendarSettings`, `DestinationCalendarSettings`, `EventAdvancedTab`, `render`
- `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.tsx` → `(anonymous)`, `FieldEditDialog`, `FormBuilder2`
- `apps/web/modules/event-types/components/tabs/advanced/RequiresConfirmationController.tsx` → `RequiresConfirmationController`
- `apps/web/modules/event-types/components/tabs/apps/EventAppsTab.tsx` → `EventAppsTab`
- `apps/web/modules/event-types/components/tabs/availability/EventAvailabilityTab.tsx` → `(anonymous)`, `EventTypeSchedule`, `TeamAvailability`, `TeamMemberSchedule`, `useCommonScheduleState`, `useRestrictionScheduleState`
- `apps/web/modules/event-types/components/tabs/availability/EventAvailabilityTabWebWrapper.tsx` → `EventAvailabilityTabWebWrapper`
- `apps/web/modules/event-types/components/tabs/setup/EventSetupTab.tsx` → `EventSetupTab`
- `apps/web/modules/event-types/components/tabs/webhooks/EventWebhooksTab.tsx` → `EventWebhooksTab`
- `apps/web/modules/form-builder/components/FormBuilderField.tsx` → `FormBuilderField`
- `apps/web/modules/onboarding/components/EmailInviteForm.tsx` → `EmailInviteForm`
- `apps/web/modules/onboarding/personal/settings/personal-settings-view.tsx` → `PersonalSettingsView`
- `apps/web/modules/schedules/components/NewScheduleButton.tsx` → `NewScheduleButton`
- `apps/web/modules/settings/components/BookerLayoutSelector.tsx` → `BookerLayoutSelector`
- `apps/web/modules/settings/my-account/appearance-view.tsx` → `AppearanceView`
- `apps/web/modules/settings/my-account/general-view.tsx` → `GeneralView`
- `apps/web/modules/settings/my-account/profile-view.tsx` → `ProfileForm`, `ProfileView`
- `apps/web/modules/settings/oauth/create/OAuthClientCreateModal.tsx` → `OAuthClientCreateDialog`
- `apps/web/modules/settings/oauth/view/OAuthClientDetailsDialog.tsx` → `OAuthClientDetailsDialog`
- `apps/web/modules/settings/outOfOffice/CreateOrEditOutOfOfficeModal.tsx` → `CreateOrEditOutOfOfficeEntryModal`
- `apps/web/modules/settings/security/password-view.tsx` → `PasswordView`
- `apps/web/modules/signup-view.tsx` → `Signup`, `UsernameField`
- `apps/web/modules/users/components/UserForm.tsx` → `UserForm`
- `apps/web/modules/users/components/UserTable/EditSheet/EditUserForm.tsx` → `EditForm`
- `apps/web/modules/webhooks/components/WebhookForm.tsx` → `WebhookForm`
- `apps/web/modules/webhooks/components/WebhookTestDisclosure.tsx` → `WebhookTestDisclosure`
- `packages/features/apps/components/AppSetDefaultLinkDialog.tsx` → `AppSetDefaultLinkDialog`
- `packages/features/apps/hooks/useAppsData.ts` → `useAppsData`
- `packages/features/bookings/Booker/hooks/useBookingForm.ts` → `useBookingForm`
- `packages/features/eventtypes/components/AssignAllTeamMembers.tsx` → `AssignAllTeamMembers`
- `packages/features/eventtypes/components/BulkEditDefaultForEventsModal.tsx` → `BulkEditDefaultForEventsModal`
- `packages/features/eventtypes/components/dialogs/HostEditDialogs.tsx` → `PriorityDialog`, `WeightDialog`
- `packages/features/eventtypes/components/tabs/limits/EventLimitsTab.tsx` → `EventLimitsTab`, `IntervalLimitsManager`, `MinimumBookingNoticeInput2`, `RangeLimitRadioItem`
- `packages/features/eventtypes/components/tabs/limits/MaxActiveBookingsPerBookerController.tsx` → `MaxActiveBookingsPerBookerController`
- `packages/features/eventtypes/components/tabs/recurring/RecurringEventController.tsx` → `RecurringEventController`
- `packages/features/form-builder/useShouldBeDisabledDueToPrefill.tsx` → `useShouldBeDisabledDueToPrefill`
- `packages/features/schedules/components/DateOverrideInputDialog.tsx` → `DateOverrideForm`
- `packages/features/schedules/components/ScheduleComponent.tsx` → `(anonymous)`, `CopyButton`, `DayRanges`, `ScheduleDay`
- `packages/platform/atoms/availability/AvailabilitySettings.tsx` → `AvailabilitySettings2`, `DateOverride`, `useExcludedDates`
- `packages/platform/atoms/connect/apple/AppleConnect.tsx` → `AppleConnect`
- `packages/platform/atoms/create-schedule/CreateScheduleForm.tsx` → `CreateScheduleForm`
- `packages/platform/atoms/event-types/hooks/useEventTypeForm.ts` → `useEventTypeForm`
- `packages/platform/atoms/event-types/wrappers/EventAvailabilityTabPlatformWrapper.tsx` → `EventAvailabilityTabPlatformWrapper`
- `packages/platform/atoms/hooks/event-types/private/useCreateEventTypeForm.ts` → `useCreateEventTypeForm`
- `packages/ui/components/address/fields.tsx` → `InputField2`, `PlainForm`, `TextField3`
- `packages/ui/components/form/inputs/Form.tsx` → `PlainForm`
- `packages/ui/components/form/inputs/HintOrErrors.tsx` → `HintsOrErrors`
- `packages/ui/components/form/inputs/Input.tsx` → `TextField`
- `packages/ui/components/form/inputs/MultiOptionInput.tsx` → `MultiOptionInput`
Existing test(s) that load `react-hook-form` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+11 more).
Currently-unexercised functions in `react-hook-form` (context only — chainstrip removes these; do NOT write tests to reach them): `$`, `Ae`, `B`, `Be`, `C`, `Ce`, `Controller`, `De`, `E`, `Ee`, `Fe`, `FormProvider` … (+99 more).

### 47. `@todesktop/client-core` — CLASSIFY 32KB — 32KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/pages/api/book/recurring-event.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (268 fns, 32KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/pages/_document.tsx` → `(anonymous)`
Currently-unexercised functions in `@todesktop/client-core` (context only — chainstrip removes these; do NOT write tests to reach them): `add`, `addBrowserView`, `addEventListenerArgsAreLegacy`, `addRepresentation`, `addWordToSpellCheckerDictionary`, `append`, `areTabsSupported`, `askForMediaAccess`, `availablePrinters`, `blur`, `bounce`, `buildFromTemplate` … (+284 more).

### 48. `@radix-ui/react-slider` — CLASSIFY 31KB — 31KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/TokenHandler/token-handler.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (81 fns, 31KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/image-uploader/Common.tsx` → `Slider`
Currently-unexercised functions in `@radix-ui/react-slider` (context only — chainstrip removes these; do NOT write tests to reach them): `BubbleInput`, `CollectionProvider`, `Provider`, `clamp`, `composeEventHandlers`, `composeRefs`, `convertValueToPercentage`, `createScope`, `getClosestValueIndex`, `getDecimalCount`, `getLabel`, `getNextSortedValues` … (+30 more).

### 49. `@lexical/rich-text` — CLASSIFY 31KB — 31KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/editor/plugins/AutoLinkPlugin.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `LexicalRichText.js (39 fns, 31KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 1 witnessed, 0 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/editor/plugins/ToolbarPlugin.tsx` → `(anonymous)`
Existing test(s) that load `@lexical/rich-text` but don't reach the functions above — **extend these**: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `packages/ui/components/editor/Editor.test.tsx`, `packages/ui/components/editor/plugins/CustomEnterKeyPlugin.test.tsx`, `packages/ui/components/editor/plugins/ToolbarPlugin.test.tsx`.
Currently-unexercised functions in `@lexical/rich-text` (context only — chainstrip removes these; do NOT write tests to reach them): `$isQuoteNode`, `A`, `B`, `E`, `F`, `H`, `I`, `J`, `K`, `L`, `blockquote`, `clone` … (+19 more).

### 50. `@radix-ui/react-checkbox` — CLASSIFY 28KB — 28KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/form/checkbox/Checkbox.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (48 fns, 28KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/form/checkbox/Checkbox.tsx` → `(anonymous)`
Existing test(s) that load `@radix-ui/react-checkbox` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+7 more).
Currently-unexercised functions in `@radix-ui/react-checkbox` (context only — chainstrip removes these; do NOT write tests to reach them): `$010c2913dbd2fe3d$export$5cae361ad82dce8b`, `$6ed0406888f73fc4$export$43e446d32b3d21af`, `$6ed0406888f73fc4$export$c7b2cbe3552a0d05`, `$6ed0406888f73fc4$var$setRef`, `$71cd76cc60e0454e$export$6f32135080cb4c3`, `$71cd76cc60e0454e$var$useUncontrolledState`, `$921a889cee6df7e8$export$99c2b779aa4e8b8b`, `$921a889cee6df7e8$var$usePresence`, `$db6c3485150b8e66$export$1ab7ae714698c4b8`, `$e42e1063c40fb3ef$export$b9ecd428b558ff10`, `$e698a72e93240346$var$BubbleInput`, `$e698a72e93240346$var$getState` … (+12 more).

### 51. `@tanstack/react-query` — CLASSIFY 27KB — 27KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `build/modern/index.js (133 fns, 27KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/app/_trpc/trpc-provider.tsx` → `TrpcProvider`
- `apps/web/components/apps/wipemycalother/confirmDialog.tsx` → `ConfirmDialog`
- `apps/web/components/GTM.tsx` → `useGeolocation`
- `apps/web/modules/bookings/hooks/useBookings.ts` → `useBookings`
- `apps/web/modules/calendars/components/CalendarSwitch.tsx` → `CalendarSwitch`
- `apps/web/modules/schedules/hooks/useApiV2AvailableSlots.ts` → `useApiV2AvailableSlots`
- `apps/web/modules/settings/outOfOffice/OutOfOfficeEntriesList.tsx` → `OutOfOfficeEntriesListContent`
- `apps/web/modules/users/components/UsersTable.tsx` → `UsersTable`
- `packages/app-store/_utils/useAddAppMutation.ts` → `useAddAppMutation`
- `packages/platform/atoms/booker/BookerPlatformWrapper.tsx` → `BookerPlatformWrapperComponent`
- `packages/platform/atoms/cal-provider/CalOAuthProvider.tsx` → `CalOAuthProvider`
- `packages/platform/atoms/cal-provider/CalProvider.tsx` → `CalProvider`
- `packages/platform/atoms/connect/conferencing-apps/ConferencingAppsViewPlatformWrapper.tsx` → `ConferencingAppsViewPlatformWrapper`
- `packages/platform/atoms/connect/conferencing-apps/hooks/useAtomBulkUpdateEventTypesToDefaultLocation.ts` → `useAtomBulkUpdateEventTypesToDefaultLocation`
- `packages/platform/atoms/connect/conferencing-apps/hooks/useAtomGetEventTypes.ts` → `useAtomGetEventTypes`
- `packages/platform/atoms/connect/conferencing-apps/hooks/useAtomsGetInstalledConferencingApps.ts` → `useAtomsGetInstalledConferencingApps`
- `packages/platform/atoms/connect/conferencing-apps/hooks/useConnect.ts` → `useConnectNonOauthApp`, `useGetZoomOauthAuthUrl`, `useOffice365GetOauthAuthUrl`
- `packages/platform/atoms/connect/conferencing-apps/hooks/useDeleteCredential.ts` → `useDeleteCredential`
- `packages/platform/atoms/connect/conferencing-apps/hooks/useGetDefaultConferencingApp.ts` → `useGetDefaultConferencingApp`
- `packages/platform/atoms/connect/conferencing-apps/hooks/useUpdateUserDefaultConferencingApp.ts` → `useUpdateUserDefaultConferencingApp`
- `packages/platform/atoms/event-types/hooks/useAddVerifiedEmail.ts` → `useAddVerifiedEmail`
- `packages/platform/atoms/event-types/hooks/useAtomEventTypeAppIntegration.ts` → `useAtomsEventTypeById`
- `packages/platform/atoms/event-types/hooks/useAtomEventTypeById.ts` → `useAtomsEventTypeById`
- `packages/platform/atoms/event-types/hooks/useAtomEventTypePaymentInfo.ts` → `useAtomsEventTypePaymentInfo`
- `packages/platform/atoms/event-types/hooks/useAtomGetAllEventTypes.ts` → `useAtomGetAllEventTypes`
- `packages/platform/atoms/event-types/hooks/useAtomHostSchedules.ts` → `useAtomHostSchedules`
- `packages/platform/atoms/event-types/hooks/useAtomUpdateEventType.ts` → `useAtomUpdateEventType`
- `packages/platform/atoms/event-types/hooks/useGetVerifiedEmails.ts` → `useGetVerifiedEmails`
- `packages/platform/atoms/event-types/wrappers/EventTypePlatformWrapper.tsx` → `EventTypePlatformWrapper2`
- `packages/platform/atoms/hooks/bookings/useBooking.ts` → `useBooking`
- `packages/platform/atoms/hooks/bookings/useBookings.ts` → `useBookings`
- `packages/platform/atoms/hooks/bookings/useCancelBooking.ts` → `useCancelBooking`
- `packages/platform/atoms/hooks/bookings/useCreateBooking.ts` → `useCreateBooking`
- `packages/platform/atoms/hooks/bookings/useCreateRecurringBooking.ts` → `useCreateRecurringBooking`
- `packages/platform/atoms/hooks/bookings/useGetBookingForReschedule.ts` → `useGetBookingForReschedule`
- `packages/platform/atoms/hooks/calendars/useAddSelectedCalendar.ts` → `useAddSelectedCalendar`
- `packages/platform/atoms/hooks/calendars/useDeleteCalendarCredentials.ts` → `useDeleteCalendarCredentials`
- `packages/platform/atoms/hooks/calendars/useRemoveSelectedCalendar.ts` → `useRemoveSelectedCalendar`
- `packages/platform/atoms/hooks/calendars/useUpdateDestinationCalendars.ts` → `useUpdateDestinationCalendars`
- `packages/platform/atoms/hooks/connect/useCheck.ts` → `useCheck`
- `packages/platform/atoms/hooks/connect/useConnect.ts` → `useGetRedirectUrl`, `useSaveCalendarCredentials`
- `packages/platform/atoms/hooks/event-types/private/useCreateEventType.ts` → `useCreateEventType`
- `packages/platform/atoms/hooks/event-types/private/useDeleteEventTypeById.ts` → `useDeleteEventTypeById`
- `packages/platform/atoms/hooks/event-types/private/useEventTypeById.ts` → `useEventTypeById`
- `packages/platform/atoms/hooks/event-types/public/useAtomGetPublicEvent.tsx` → `useAtomGetPublicEvent`
- `packages/platform/atoms/hooks/event-types/public/useEventType.ts` → `useEventType`
- `packages/platform/atoms/hooks/event-types/public/useEventTypes.ts` → `useEventTypes`
- `packages/platform/atoms/hooks/organizations/bookings/useOrganizationBookings.ts` → `useOrganizationBookings`
- `packages/platform/atoms/hooks/organizations/bookings/useOrganizationUserBookings.ts` → `useOrganizationUserBookings`
- `packages/platform/atoms/hooks/schedules/useAtomCreateSchedule.ts` → `useAtomCreateSchedule`
- `packages/platform/atoms/hooks/schedules/useAtomDuplicateSchedule.ts` → `useAtomDuplicateSchedule`
- `packages/platform/atoms/hooks/schedules/useAtomGetAllSchedules.ts` → `useAtomGetAllSchedules`
- `packages/platform/atoms/hooks/schedules/useAtomSchedule.ts` → `useAtomSchedule`
- `packages/platform/atoms/hooks/schedules/useAtomUpdateSchedule.ts` → `useAtomUpdateSchedule`
- `packages/platform/atoms/hooks/schedules/useDeleteSchedule.ts` → `useDeleteSchedule`
- `packages/platform/atoms/hooks/schedules/useSchedule.ts` → `useSchedule`
- `packages/platform/atoms/hooks/schedules/useSchedules.ts` → `useSchedules`
- `packages/platform/atoms/hooks/schedules/useUpdateSchedule.ts` → `useUpdateSchedule`
- `packages/platform/atoms/hooks/stripe/useCheck.ts` → `useCheck`
- `packages/platform/atoms/hooks/stripe/useConnect.ts` → `useGetRedirectUrl`
- `packages/platform/atoms/hooks/useAvailableSlots.ts` → `useAvailableSlots`
- `packages/platform/atoms/hooks/useCalendarsBusyTimes.ts` → `useCalendarsBusyTimes`
- `packages/platform/atoms/hooks/useConnectedCalendars.tsx` → `useConnectedCalendars`
- `packages/platform/atoms/hooks/useDeleteSelectedSlot.ts` → `useDeleteSelectedSlot`
- `packages/platform/atoms/hooks/useEventTypesList.tsx` → `useEventTypesList`
- `packages/platform/atoms/hooks/useGetCityTimezones.ts` → `useGetCityTimezones`
- `packages/platform/atoms/hooks/useMe.ts` → `useMe`
- `packages/platform/atoms/hooks/useReserveSlot.ts` → `useReserveSlot`
- `packages/platform/atoms/hooks/useScheduleByEventSlug.tsx` → `useScheduleByEventSlug`
- `packages/platform/atoms/hooks/useUpdateUserTimezone.ts` → `useUpdateUserTimezone`
- `packages/platform/atoms/hooks/useVerifyCode.ts` → `useVerifyCode`
- `packages/platform/atoms/hooks/useVerifyEmail.ts` → `useVerifyEmail`
Existing test(s) that load `@tanstack/react-query` but don't reach the functions above — **extend these**: `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts`, `apps/web/modules/users/views/users-public-view.test.tsx`.
Currently-unexercised functions in `@tanstack/react-query` (context only — chainstrip removes these; do NOT write tests to reach them): `HydrationBoundary`, `QueryErrorResetBoundary`, `addSignalProperty`, `addToEnd`, `addToStart`, `cancel`, `cancelQueries`, `clear`, `combineResult`, `constructor`, `continue`, `continueFn` … (+89 more).

### 52. `@radix-ui/react-collapsible` — CLASSIFY 22KB — 22KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (39 fns, 22KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/bookings/views/bookings-single-view.tsx` → `RecurringBookings`
- `apps/web/modules/embed/components/Embed.tsx` → `EmailEmbed`, `EmbedTypeCodeAndPreviewDialogContent`
Currently-unexercised functions in `@radix-ui/react-collapsible` (context only — chainstrip removes these; do NOT write tests to reach them): `$409067139f391064$var$getState`, `$6ed0406888f73fc4$export$43e446d32b3d21af`, `$6ed0406888f73fc4$export$c7b2cbe3552a0d05`, `$6ed0406888f73fc4$var$setRef`, `$71cd76cc60e0454e$export$6f32135080cb4c3`, `$71cd76cc60e0454e$var$useUncontrolledState`, `$921a889cee6df7e8$export$99c2b779aa4e8b8b`, `$921a889cee6df7e8$var$usePresence`, `$fe963b355347cc68$export$3e6543de14f8614f`, `Provider`, `_extends`, `createScope` … (+5 more).

### 53. `@trpc/client` — CLASSIFY 22KB — 22KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (31 fns, 22KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 0 witnessed, 1 unreached — stated reasons: "Skipping `fn:@trpc/client/dist/index.mjs@34143` (`createWSClient`) — the listed app call paths only import `httpBatchLink`, `httpLink`, `loggerLink`, `splitLink`, `TRPCClientError(Like)`; none reference `wsLink`/`createWSClient`, so there's no evidence this app path stands up a WebSocket tRPC client.". (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/app/_trpc/query-client.ts` → `isTRPCClientError`
- `apps/web/app/_trpc/trpc-client.ts` → `(anonymous)`
- `apps/web/modules/connect-and-join/connect-and-join-view.tsx` → `onError`
- `apps/web/modules/event-types/views/event-types-listing-view.tsx` → `onError`
- `packages/trpc/react/trpc.ts` → `(anonymous)`, `config`
Existing test(s) that load `@trpc/client` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts`, `apps/web/modules/users/views/users-public-view.test.tsx`.
Currently-unexercised functions in `@trpc/client` (context only — chainstrip removes these; do NOT write tests to reach them): `cancel`, `clientCallTypeToProcedureType`, `complete`, `constructor`, `createTRPCClient`, `createTRPCClientProxy`, `createWSClient`, `deserialize`, `error`, `exponentialBackoff`, `formDataRequester`, `getBody` … (+19 more).

### 54. `nuqs` — CLASSIFY 22KB — 22KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (34 fns, 11KB)`, `chainstrip-chunk-Oz2jKEgd.mjs (25 fns, 8KB)`, `dist/adapters/next/pages.js (3 fns, 2KB)`, `dist/adapters/next/app.js (3 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/lib/app-providers-app-dir.tsx` → `AppProviders`
- `apps/web/lib/app-providers.tsx` → `AppProviders`
- `apps/web/modules/bookings/hooks/useActiveSegmentFromUrl.ts` → `useActiveSegmentFromUrl`
- `apps/web/modules/bookings/hooks/useBookingsView.ts` → `useBookingsView`
- `apps/web/modules/bookings/hooks/useCurrentWeekStart.ts` → `useCurrentWeekStart`
- `apps/web/modules/bookings/hooks/useSelectedBookingId.ts` → `useSelectedBookingId`
- `apps/web/modules/bookings/hooks/useSelectedBookingUid.ts` → `useSelectedBookingUid`
- `apps/web/modules/data-table/contexts/DataTableStateContext.tsx` → `DataTableStateProvider`
- `apps/web/modules/shell/hooks/useWelcomeToCalcomModal.ts` → `useWelcomeToCalcomModal`
- `apps/web/modules/users/components/UserTable/BulkActions/DynamicLink.tsx` → `DynamicLink`
- `apps/web/modules/users/components/UserTable/UserListTable.tsx` → `UserListTableContent`
- `packages/features/data-table/lib/parsers.ts` → `parse`
- `packages/ui/components/form/wizard/useWizardState.ts` → `createStepParser`, `useWizardState`
Existing test(s) that load `nuqs` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` … (+8 more).
Currently-unexercised functions in `nuqs` (context only — chainstrip removes these; do NOT write tests to reach them): `abort`, `applyPendingUpdates`, `compareDates`, `compose`, `constructor`, `createLoader`, `createMultiParser`, `createStandardSchemaV1`, `debounce`, `emit`, `encodeQueryValue`, `eq` … (+40 more).

### 55. `react-error-boundary` — UNLOCK ≤22KB — its extraction already ships on BUILD evidence only (no test). A test upgrades the evidence AND lets covtrim stub its dead functions — up to ~22KB, unmeasured until a test loads it.
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/components/phone-input/PhoneInput.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Witness probes so far: 0 witnessed, 1 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/error/BookingPageErrorBoundary.tsx` → `BookingPageErrorBoundary`

### 56. `entities` — CLASSIFY 21KB — 21KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/emails/templates/admin-oauth-client-notification.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lib/esm/decode.js (18 fns, 8KB)`, `chainstrip-chunk-BxOBVbaL.cjs (18 fns, 6KB)`, `lib/index.js (5 fns, 3KB)`, `lib/esm/index.js (4 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/emails/templates/_base-email.ts` → `sendEmail`
Existing test(s) that load `entities` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `apps/web/lib/daily-webhook/tests/recorded-daily-video.test.ts`, `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx` … (+51 more).
Currently-unexercised functions in `entities` (context only — chainstrip removes these; do NOT write tests to reach them): `addToNumericResult`, `decode`, `decode$1`, `decodeCodePoint`, `decodeHTML`, `decodeHTMLAttribute`, `decodeHTMLStrict`, `decodeStrict`, `decodeWithTrie`, `decodeXML`, `determineBranch`, `emitNamedEntityData` … (+21 more).

### 57. `@getalby/lightning-tools` — CLASSIFY 19KB — 19KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/BookingPageTagManager.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.modern.js (68 fns, 19KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/alby/components/AlbyPriceComponent.tsx` → `(anonymous)`
- `packages/app-store/alby/lib/PaymentService.ts` → `create`
Currently-unexercised functions in `@getalby/lightning-tools` (context only — chainstrip removes these; do NOT write tests to reach them): `$`, `1`, `13`, `16`, `19`, `23`, `27`, `3`, `5`, `E`, `F`, `J` … (+66 more).

### 58. `react-schemaorg` — UNLOCK ≤17KB — its extraction already ships on BUILD evidence only (no test). A test upgrades the evidence AND lets covtrim stub its dead functions — up to ~17KB, unmeasured until a test loads it.
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/components/phone-input/PhoneInput.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Witness probes so far: 1 witnessed, 0 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/schemas/EventReservationSchema.tsx` → `EventReservationSchema`

### 59. `@radix-ui/react-dialog` — CLASSIFY 13KB — 13KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/dialog/dialog.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (47 fns, 13KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/components/controlled-dialog/index.tsx` → `Dialog`
- `packages/ui/components/dialog/ConfirmationDialogContent.tsx` → `ConfirmationContent`
- `packages/ui/components/dialog/Dialog.tsx` → `(anonymous)`, `Dialog`, `DialogClose`
- `packages/ui/components/sheet/Sheet.tsx` → `(anonymous)`, `Sheet`
Existing test(s) that load `@radix-ui/react-dialog` but don't reach the functions above — **extend these**: `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/data-table/components/filters/ColumnVisibilityButton.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/schedules/components/date-override-list.test.tsx` … (+4 more).
Currently-unexercised functions in `@radix-ui/react-dialog` (context only — chainstrip removes these; do NOT write tests to reach them): `$5cb92bef7577960e$var$handleAndDispatchCustomEvent`, `$8927f6f2acc4f386$export$6d1a0317bde7de7f`, `$d3863c46a17e8a28$var$findVisible`, `$d3863c46a17e8a28$var$getTabbableEdges`, `$d3863c46a17e8a28$var$isHidden`, `Provider`, `__spreadArray`, `alwaysContainsScroll`, `assignMedium`, `assignSyncMedium`, `createScope`, `createScope1` … (+22 more).

### 60. `@formkit/auto-animate` — CLASSIFY 13KB — 13KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `react/index.mjs (26 fns, 13KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/dialog/ReassignDialog.tsx` → `ReassignDialog`
- `apps/web/modules/apps/components/AllApps.tsx` → `AllApps`
- `apps/web/modules/availability/availability-view.tsx` → `AvailabilityList`
- `apps/web/modules/event-types/components/CheckedUserSelect.tsx` → `CheckedUserSelect`
- `apps/web/modules/event-types/components/EventType.tsx` → `EventType`
- `apps/web/modules/event-types/components/locations/CalVideoSettings.tsx` → `CalVideoSettings`
- `apps/web/modules/event-types/components/locations/Locations.tsx` → `Locations`
- `apps/web/modules/event-types/components/MultiplePrivateLinksController.tsx` → `MultiplePrivateLinksController`
- `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.tsx` → `FormBuilder2`, `Options`
- `apps/web/modules/event-types/components/tabs/availability/EventAvailabilityTab.tsx` → `TeamAvailability`
- `apps/web/modules/event-types/views/event-types-listing-view.tsx` → `InfiniteEventTypeList`
- `packages/app-store/_components/AppCard.tsx` → `AppCard`
- `packages/app-store/_components/AppCategoryNavigation.tsx` → `AppCategoryNavigation`
- `packages/features/eventtypes/components/CheckedTeamSelect.tsx` → `CheckedTeamSelect`
- `packages/features/eventtypes/components/ChildrenEventTypeSelect.tsx` → `ChildrenEventTypeSelect`
- `packages/features/eventtypes/components/tabs/limits/EventLimitsTab.tsx` → `IntervalLimitsManager`
- `packages/platform/atoms/event-types/wrappers/ListEventTypesPlatformWrapper.tsx` → `ListEventTypesPlatformWrapper`
- `packages/platform/atoms/list-schedules/wrappers/ListSchedulesPlatformWrapper.tsx` → `ListSchedulesPlatformWrapper`
- `packages/ui/components/card/PanelCard.tsx` → `PanelCard`
- `packages/ui/components/form/inputs/MultiOptionInput.tsx` → `MultiOptionInput`
- `packages/ui/components/form/switch/SettingsToggle.tsx` → `SettingsToggle`
- `packages/ui/components/section/section.tsx` → `Root`, `SubSection`
Existing test(s) that load `@formkit/auto-animate` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+7 more).
Currently-unexercised functions in `@formkit/auto-animate` (context only — chainstrip removes these; do NOT write tests to reach them): `add`, `animate`, `autoAnimate`, `cleanUp`, `deletePosition`, `disable`, `enable`, `forEach`, `getCoords`, `getElements`, `getOptions`, `getTarget` … (+12 more).

### 61. `@lexical/utils` — CLASSIFY 13KB — 13KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/editor/plugins/AutoLinkPlugin.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `LexicalUtils.js (17 fns, 13KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Witness probes so far: 0 witnessed, 1 unreached — stated reasons: "Skipping `fn:@lexical/utils/LexicalUtils.js@877` (`requireLexicalUtils_dev`) — reaching `mergeRegister`'s real usage requires a fully mounted `LexicalComposer` editor context around `ToolbarPlugin.tsx`, whose full prop/provider requirements aren't visible here; assembling that scaffolding blind risks an unreliable/non-deterministic probe.". (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/editor/plugins/ToolbarPlugin.tsx` → `(anonymous)`
Existing test(s) that load `@lexical/utils` but don't reach the functions above — **extend these**: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `packages/ui/components/editor/Editor.test.tsx`, `packages/ui/components/editor/plugins/ToolbarPlugin.test.tsx`.
Currently-unexercised functions in `@lexical/utils` (context only — chainstrip removes these; do NOT write tests to reach them): `$dfs`, `$getNearestBlockElementAncestorOrThrow`, `$getNearestNodeOfType`, `$insertNodeToNearestRoot`, `$restoreEditorState`, `$wrapNodeInElement`, `addClassNamesToElement`, `h`, `isHTMLAnchorElement`, `mediaFileReader`, `p`, `q` … (+4 more).

### 62. `date-fns-tz` — CLASSIFY 12KB — 12KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/booking-audit/lib/actions/AuditActionServiceHelper.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/esm/index.js (29 fns, 12KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/booking-audit/lib/actions/AuditActionServiceHelper.ts` → `formatDateInTimeZone`, `formatDateTimeInTimeZone`
- `packages/features/schedules/components/DateOverrideList.tsx` → `(anonymous)`, `timeSpan`
Existing test(s) that load `date-fns-tz` but don't reach the functions above — **extend these**: `apps/web/modules/schedules/components/date-override-list.test.tsx`, `packages/features/booking-audit/lib/actions/AuditActionServiceHelper.test.ts`, `packages/features/booking-audit/lib/actions/__tests__/AcceptedAuditActionService.test.ts`, `packages/features/booking-audit/lib/actions/__tests__/AttendeeAddedAuditActionService.test.ts`, `packages/features/booking-audit/lib/actions/__tests__/AttendeeRemovedAuditActionService.test.ts` … (+11 more).
Currently-unexercised functions in `date-fns-tz` (context only — chainstrip removes these; do NOT write tests to reach them): `O`, `X`, `addLeadingZeros`, `dayOfISOWeekYear`, `fixOffset`, `formatTimezone`, `formatTimezoneShort`, `formatTimezoneWithOptionalMinutes`, `fromZonedTime`, `getDTF`, `getTimeZoneOffset`, `getTimezoneOffset` … (+18 more).

### 63. `ipaddr.js` — CLASSIFY 12KB — 12KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/lib/CalEventParser.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lib/ipaddr.js (27 fns, 12KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/lib/ssrfProtection.ts` → `isPrivateIP`, `validateUrlCore`
Existing test(s) that load `ipaddr.js` but don't reach the functions above — **extend these**: `packages/lib/ssrfProtection.test.ts`.
Currently-unexercised functions in `ipaddr.js` (context only — chainstrip removes these; do NOT write tests to reach them): `broadcastAddressFromCIDR`, `fromByteArray`, `isIPv4`, `isIPv6`, `isValidCIDR`, `isValidCIDRFourPartDecimal`, `isValidFourPartDecimal`, `networkAddressFromCIDR`, `padPart`, `parseCIDR`, `prefixLengthFromSubnetMask`, `process` … (+7 more).

### 64. `superjson` — CLASSIFY 12KB — 12KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/lib/CalEventParser.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (46 fns, 7KB)`, `dist/esm/index.js (33 fns, 5KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/lib/unstable_cache/unstable_cache.ts` → `(anonymous)`, `wrap`
- `packages/trpc/react/trpc.ts` → `config`
Existing test(s) that load `superjson` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts`, `apps/web/modules/users/views/users-public-view.test.tsx`, `packages/trpc/server/routers/viewer/eventTypes/__tests__/util.test.ts`.
Currently-unexercised functions in `superjson` (context only — chainstrip removes these; do NOT write tests to reach them): `__assign`, `__read2`, `__read3`, `__spreadArray`, `__spreadArray2`, `allowErrorProps`, `apply`, `applyReferentialEqualityAnnotations`, `clear`, `escapeKey`, `findByName`, `getAllowedProps` … (+45 more).

### 65. `marked` — CLASSIFY 12KB — 12KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/platform/atoms/lib/markdownToSafeHTML.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lib/marked.esm.js (33 fns, 12KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/platform/atoms/lib/markdownToSafeHTML.ts` → `markdownToSafeHTML`
Existing test(s) that load `marked` but don't reach the functions above — **extend these**: `packages/platform/atoms/lib/markdownToSafeHTML.test.ts`.
Currently-unexercised functions in `marked` (context only — chainstrip removes these; do NOT write tests to reach them): `blockquote`, `br`, `checkbox`, `code`, `codespan`, `constructor`, `del`, `em`, `exec`, `getEscapeReplacement`, `heading`, `hooksProp` … (+26 more).

### 66. `@lexical/link` — CLASSIFY 11KB — 11KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/editor/plugins/AutoLinkPlugin.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `LexicalLink.js (13 fns, 11KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/editor/plugins/ToolbarPlugin.tsx` → `(anonymous)`, `onKeyDown`
Existing test(s) that load `@lexical/link` but don't reach the functions above — **extend these**: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `packages/ui/components/editor/Editor.test.tsx`, `packages/ui/components/editor/plugins/CustomEnterKeyPlugin.test.tsx`, `packages/ui/components/editor/plugins/ToolbarPlugin.test.tsx`.
Currently-unexercised functions in `@lexical/link` (context only — chainstrip removes these; do NOT write tests to reach them): `a`, `canBeEmpty`, `canInsertTextAfter`, `canInsertTextBefore`, `clone`, `constructor`, `createDOM`, `exportJSON`, `extractWithChild`, `getRel`, `getTarget`, `getURL` … (+14 more).

### 67. `@next/third-parties` — CLASSIFY 10KB — 10KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/components/phone-input/PhoneInput.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/google/index.js (18 fns, 10KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/GTM.tsx` → `GoogleTagManagerComponent`
Currently-unexercised functions in `@next/third-parties` (context only — chainstrip removes these; do NOT write tests to reach them): `GoogleAnalytics`, `GoogleMapsEmbed`, `GoogleTagManager`, `ThirdPartyScriptEmbed$1`, `YouTubeEmbed`, `createHtml`, `filterArgs`, `formatData`, `formatUrl`, `get`, `sendGAEvent`, `sendGTMEvent`.

### 68. `@trpc/react-query` — CLASSIFY 10KB — 10KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `chainstrip-chunk-Bk0SdB1D.mjs (37 fns, 9KB)`, `dist/index.mjs (2 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/event-types/components/EventTypeWebWrapper.tsx` → `onError`
Existing test(s) that load `@trpc/react-query` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/hooks/useActiveFiltersValidator.test.ts`, `apps/web/modules/users/views/users-public-view.test.tsx`.
Currently-unexercised functions in `@trpc/react-query` (context only — chainstrip removes these; do NOT write tests to reach them): `cancel`, `cancelQuery`, `createQueryUtilsProxy`, `createUseQueries`, `ensureData`, `ensureQueryData`, `fetch`, `fetchInfinite`, `fetchInfiniteQuery`, `fetchQuery`, `getData`, `getInfiniteData` … (+24 more).

### 69. `@trpc/server` — CLASSIFY 9KB — 9KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/trpc/server/routers/viewer/availability/schedule/getAllSchedulesByUserId.handler.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `chainstrip-chunk-CaZKo1vi.mjs (10 fns, 5KB)`, `dist/observable/index.mjs (5 fns, 1KB)`, `dist/http.mjs (3 fns, 1KB)`, `dist/unstable-core-do-not-import/index.mjs (6 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/app/api/defaultResponderForAppDir.ts` → `(anonymous)`
- `apps/web/app/api/link/route.ts` → `handler`
- `apps/web/app/api/verify-booking-token/route.ts` → `handleBookingAction`
- `packages/features/eventtypes/lib/getEventTypeById.ts` → `getEventTypeById`
- `packages/trpc/server/createNextApiHandler.ts` → `createNextApiHandler`
- `packages/trpc/server/lib/toTRPCError.ts` → `convertErrorWithCodeToTRPCError`
- `packages/trpc/server/middlewares/sessionMiddleware.ts` → `(anonymous)`
- `packages/trpc/server/onErrorHandler.ts` → `onErrorHandler`
- `packages/trpc/server/procedures/pbacProcedures.ts` → `(anonymous)`
- `packages/trpc/server/routers/loggedInViewer/addNotificationsSubscription.handler.ts` → `addNotificationsSubscriptionHandler`
- `packages/trpc/server/routers/loggedInViewer/addSecondaryEmail.handler.ts` → `addSecondaryEmailHandler`
- `packages/trpc/server/routers/loggedInViewer/connectAndJoin.handler.ts` → `Handler`
- `packages/trpc/server/routers/loggedInViewer/eventTypeOrder.handler.ts` → `eventTypeOrderHandler`
- `packages/trpc/server/routers/loggedInViewer/stripeCustomer.handler.ts` → `stripeCustomerHandler`
- `packages/trpc/server/routers/loggedInViewer/teamsAndUserProfilesQuery.handler.ts` → `teamsAndUserProfilesQuery`
- `packages/trpc/server/routers/viewer/admin/createCoupon.handler.ts` → `createCoupon`
- `packages/trpc/server/routers/viewer/admin/setSMSLockState.handler.ts` → `setSMSLockState`
- `packages/trpc/server/routers/viewer/admin/watchlist/bulkDelete.handler.ts` → `bulkDeleteWatchlistEntriesHandler`
- `packages/trpc/server/routers/viewer/admin/watchlist/create.handler.ts` → `createWatchlistEntryHandler`
- `packages/trpc/server/routers/viewer/admin/watchlist/delete.handler.ts` → `deleteWatchlistEntryHandler`
- `packages/trpc/server/routers/viewer/admin/watchlist/getDetails.handler.ts` → `getWatchlistEntryDetailsHandler`
- `packages/trpc/server/routers/viewer/apiKeys/_auth-middleware.ts` → `checkPermissions`
- `packages/trpc/server/routers/viewer/apps/appById.handler.ts` → `appByIdHandler`
- `packages/trpc/server/routers/viewer/apps/saveKeys.handler.ts` → `saveKeysHandler`
- `packages/trpc/server/routers/viewer/apps/toggle.handler.ts` → `toggleHandler`
- `packages/trpc/server/routers/viewer/apps/updateAppCredentials.handler.ts` → `handleCustomValidations`, `updateAppCredentialsHandler`
- `packages/trpc/server/routers/viewer/apps/updateUserDefaultConferencingApp.handler.ts` → `updateUserDefaultConferencingAppHandler`
- `packages/trpc/server/routers/viewer/auth/changePassword.handler.ts` → `changePasswordHandler`
- `packages/trpc/server/routers/viewer/auth/createAccountPassword.handler.ts` → `createAccountPasswordHandler`
- `packages/trpc/server/routers/viewer/auth/resendVerifyEmail.handler.ts` → `resendVerifyEmail`
- `packages/trpc/server/routers/viewer/auth/verifyCodeUnAuthenticated.handler.ts` → `verifyCodeUnAuthenticatedHandler`
- `packages/trpc/server/routers/viewer/auth/verifyPassword.handler.ts` → `verifyPasswordHandler`
- `packages/trpc/server/routers/viewer/availability/calendarOverlay.handler.ts` → `(anonymous)`, `calendarOverlayHandler`
- `packages/trpc/server/routers/viewer/availability/schedule/bulkUpdateDefaultAvailability.handler.ts` → `bulkUpdateToDefaultAvailabilityHandler`
- `packages/trpc/server/routers/viewer/availability/schedule/create.handler.ts` → `createHandler`
- `packages/trpc/server/routers/viewer/availability/schedule/delete.handler.ts` → `deleteHandler`
- `packages/trpc/server/routers/viewer/availability/schedule/duplicate.handler.ts` → `duplicateHandler`
- `packages/trpc/server/routers/viewer/availability/schedule/getAllSchedulesByUserId.handler.ts` → `getAllSchedulesByUserIdHandler`
- `packages/trpc/server/routers/viewer/availability/team/listTeamAvailability.handler.ts` → `getInfoForAllTeams`
- `packages/trpc/server/routers/viewer/availability/user.handler.ts` → `userHandler`
- `packages/trpc/server/routers/viewer/bookings/addGuests.handler.ts` → `getBooking`, `getOrganizerData`, `sanitizeAndFilterGuests`, `updateCalendarEvent`, `validateGuestsFieldEnabled`, `validateUserPermissions`
- `packages/trpc/server/routers/viewer/bookings/confirm.handler.ts` → `confirmHandler`
- `packages/trpc/server/routers/viewer/bookings/editLocation.handler.ts` → `getLocationInEvtFormatOrThrow`
- `packages/trpc/server/routers/viewer/bookings/get.handler.ts` → `getAttendeeEmailsFromUserIdsFilter`, `getBookings`, `getEventTypeIdsFromEventTypeIdsFilter`
- `packages/trpc/server/routers/viewer/bookings/getBookingHistory.handler.ts` → `getBookingHistoryHandler`
- `packages/trpc/server/routers/viewer/bookings/hasWrongAssignmentReport.handler.ts` → `hasWrongAssignmentReportHandler`
- `packages/trpc/server/routers/viewer/bookings/reportBooking.handler.ts` → `reportBookingHandler`
- `packages/trpc/server/routers/viewer/bookings/reportWrongAssignment.handler.ts` → `reportWrongAssignmentHandler`
- `packages/trpc/server/routers/viewer/bookings/requestReschedule.handler.ts` → `requestRescheduleHandler`
- `packages/trpc/server/routers/viewer/bookings/updateWrongAssignmentReportStatus.handler.ts` → `updateWrongAssignmentReportStatusHandler`
- `packages/trpc/server/routers/viewer/bookings/util.ts` → `(anonymous)`
- `packages/trpc/server/routers/viewer/calendars/setDestinationCalendar.handler.ts` → `setDestinationCalendarHandler`
- `packages/trpc/server/routers/viewer/calVideo/getCalVideoRecordings.handler.ts` → `getCalVideoRecordingsHandler`
- `packages/trpc/server/routers/viewer/calVideo/getDownloadLinkOfCalVideoRecordings.handler.ts` → `getDownloadLinkOfCalVideoRecordingsHandler`
- `packages/trpc/server/routers/viewer/calVideo/getMeetingInformation.handler.ts` → `getMeetingInformationHandler`
- `packages/trpc/server/routers/viewer/eventTypes/bulkUpdateToDefaultLocation.handler.ts` → `bulkUpdateToDefaultLocationHandler`
- `packages/trpc/server/routers/viewer/eventTypes/getActiveOnOptions.handler.ts` → `getActiveOnOptions`
- `packages/trpc/server/routers/viewer/eventTypes/getHashedLink.handler.ts` → `getHashedLinkHandler`
- `packages/trpc/server/routers/viewer/eventTypes/getHostsWithLocationOptions.handler.ts` → `getHostsWithLocationOptionsHandler`
- `packages/trpc/server/routers/viewer/eventTypes/getUserEventGroups.handler.ts` → `getUserEventGroups`
- `packages/trpc/server/routers/viewer/eventTypes/heavy/create.handler.ts` → `createHandler`
- `packages/trpc/server/routers/viewer/eventTypes/heavy/duplicate.handler.ts` → `duplicateHandler`
- `packages/trpc/server/routers/viewer/eventTypes/heavy/update.handler.ts` → `updateHandler`
- `packages/trpc/server/routers/viewer/eventTypes/massApplyHostLocation.handler.ts` → `massApplyHostLocationHandler`
- `packages/trpc/server/routers/viewer/eventTypes/util.ts` → `(anonymous)`, `ensureEmailOrPhoneNumberIsPresent`
- `packages/trpc/server/routers/viewer/holidays/toggleHoliday.handler.ts` → `toggleHolidayHandler`
- `packages/trpc/server/routers/viewer/holidays/updateSettings.handler.ts` → `updateSettingsHandler`
- `packages/trpc/server/routers/viewer/me/updateProfile.handler.ts` → `updateProfileHandler`
- `packages/trpc/server/routers/viewer/oAuth/deleteClient.handler.ts` → `deleteClientHandler`
- `packages/trpc/server/routers/viewer/oAuth/generateAuthCode.handler.ts` → `generateAuthCodeHandler`
- `packages/trpc/server/routers/viewer/oAuth/getClientForAuthorization.handler.ts` → `getClientForAuthorizationHandler`
- `packages/trpc/server/routers/viewer/oAuth/updateClient.handler.ts` → `updateClientHandler`
- `packages/trpc/server/routers/viewer/ooo/outOfOfficeCreateOrUpdate.handler.ts` → `outOfOfficeCreateOrUpdate`
- `packages/trpc/server/routers/viewer/ooo/outOfOfficeEntriesList.handler.ts` → `outOfOfficeEntriesList`
- `packages/trpc/server/routers/viewer/ooo/outOfOfficeEntryDelete.handler.ts` → `outOfOfficeEntryDelete`
- `packages/trpc/server/routers/viewer/payments/chargeCard.handler.ts` → `chargeCardHandler`
- `packages/trpc/server/routers/viewer/slots/reserveSlot.handler.ts` → `reserveSlotHandler`
- `packages/trpc/server/routers/viewer/slots/util.ts` → `(anonymous)`, `_getAvailableSlots`, `_getDynamicEventType`, `_mapWithinBoundsSlotsToDate`, `getEventTypeId`
- `packages/trpc/server/routers/viewer/users/_router.ts` → `(anonymous)`
- `packages/trpc/server/routers/viewer/webhook/create.handler.ts` → `createHandler`
- `packages/trpc/server/routers/viewer/webhook/edit.handler.ts` → `editHandler`
- `packages/trpc/server/routers/viewer/webhook/util.ts` → `(anonymous)`
Existing test(s) that load `@trpc/server` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions-cleanup/__tests__/route.test.ts`, `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/cron/selected-calendars/__tests__/cron.test.ts`, `apps/web/app/api/defaultResponderForAppDir.test.ts`, `apps/web/app/api/link/__tests__/route.test.ts` … (+29 more).
Currently-unexercised functions in `@trpc/server` (context only — chainstrip removes these; do NOT write tests to reach them): `assertIsJSONRPC2OrUndefined`, `assertIsObject`, `assertIsProcedureType`, `assertIsRequestId`, `assertIsString`, `callProc`, `caughtErrorToData`, `constructor`, `createCaller`, `createCallerInner`, `defaultFormatter`, `deserialize` … (+15 more).

### 70. `@prisma/adapter-pg` — CLASSIFY 8KB — 8KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/prisma/zod-utils.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (23 fns, 8KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/prisma/index.ts` → `customPrisma`
Existing test(s) that load `@prisma/adapter-pg` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/selected-calendars/__tests__/cron.test.ts`, `apps/web/lib/daily-webhook/tests/recorded-daily-video.test.ts`, `apps/web/pages/api/book/recurring-event.test.ts`, `apps/web/test/handlers/requestReschedule.test.ts`, `apps/web/test/lib/getSchedule.test.ts` … (+66 more).
Currently-unexercised functions in `@prisma/adapter-pg` (context only — chainstrip removes these; do NOT write tests to reach them): `$`, `bgBlack`, `bgBlue`, `bgCyan`, `bgGreen`, `bgMagenta`, `bgRed`, `bgWhite`, `bgYellow`, `black`, `blue`, `bold` … (+46 more).

### 71. `@urql/exchange-retry` — CLASSIFY 8KB — 8KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/salesforce/lib/graphql/__tests__/SalesforceGraphQLClient.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/urql-exchange-retry.mjs (12 fns, 8KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/salesforce/lib/graphql/SalesforceGraphQLClient.ts` → `constructor`
Existing test(s) that load `@urql/exchange-retry` but don't reach the functions above — **extend these**: `packages/app-store/salesforce/lib/__tests__/CrmService.integration.test.ts`, `packages/app-store/salesforce/lib/graphql/__tests__/SalesforceGraphQLClient.test.ts`, `packages/features/crmManager/crmManager.test.ts`.
Currently-unexercised functions in `@urql/exchange-retry` (context only — chainstrip removes these; do NOT write tests to reach them): `asyncIteratorSymbol`, `debounce`, `filter`, `fromAsyncIterable`, `fromIterable`, `fromValue`, `identity`, `make`, `makeSubject`, `merge`, `mergeAll`, `mergeMap` … (+5 more).

### 72. `@formbricks/js` — UNLOCK ≤6KB — its extraction already ships on BUILD evidence only (no test). A test upgrades the evidence AND lets covtrim stub its dead functions — up to ~6KB, unmeasured until a test loads it.
Runner evidence: `apps/web/modules/signup-view.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Witness probes so far: 0 witnessed, 1 unreached. (A stated unreachable-through-the-app reason is evidence for the report — never a removal.)
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/formbricks/hooks/useFormbricks.ts` → `initFormbricks`
- `apps/web/modules/formbricks/lib/trackFormbricksAction.ts` → `trackFormbricksAction`

### 73. `@lexical/html` — CLASSIFY 6KB — 6KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/editor/plugins/AutoLinkPlugin.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `LexicalHtml.js (1 fns, 6KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/editor/plugins/ToolbarPlugin.tsx` → `(anonymous)`
Existing test(s) that load `@lexical/html` but don't reach the functions above — **extend these**: `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `packages/ui/components/editor/Editor.test.tsx`, `packages/ui/components/editor/plugins/ToolbarPlugin.test.tsx`.
Currently-unexercised functions in `@lexical/html` (context only — chainstrip removes these; do NOT write tests to reach them): `requireLexicalHtml_dev`.

### 74. `zustand` — CLASSIFY 6KB — 6KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/components/booking/actions/bookingActions.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `chainstrip-chunk-DWjJzDf2.mjs (11 fns, 6KB)`, `esm/shallow.mjs (1 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/booking/actions/BookingActionsStoreProvider.tsx` → `useBookingActionsStoreContext`
- `apps/web/components/booking/actions/store.ts` → `createBookingActionsStore`
- `apps/web/modules/bookings/components/AvailableTimesHeader.tsx` → `AvailableTimesHeader`
- `apps/web/modules/bookings/components/Booker.tsx` → `BookerComponent`
- `apps/web/modules/bookings/components/BookerWebWrapper.tsx` → `BookerWebWrapperComponent`
- `apps/web/modules/bookings/components/DatePicker.tsx` → `DatePicker`
- `apps/web/modules/bookings/components/EventMeta.tsx` → `EventMeta`
- `apps/web/modules/bookings/components/SlotSelectionModalHeader.tsx` → `SlotSelectionModalHeader`
- `apps/web/modules/bookings/hooks/useBookings.ts` → `useBookings`
- `apps/web/modules/bookings/hooks/useCalendars.ts` → `useCalendars`
- `apps/web/modules/bookings/hooks/useOverlayCalendar.ts` → `useOverlayCalendar`
- `apps/web/modules/bookings/hooks/useSlots.ts` → `useSlots`
- `apps/web/modules/bookings/store/bookingDetailsSheetStore.tsx` → `createBookingDetailsSheetStore`, `useBookingDetailsSheetStore`
- `apps/web/modules/calendars/weeklyview/components/blocking/BlockedList.tsx` → `BlockedList`
- `apps/web/modules/calendars/weeklyview/components/event/Empty.tsx` → `Cell`
- `apps/web/modules/calendars/weeklyview/components/event/EventList.tsx` → `EventList`
- `apps/web/modules/embed/components/Embed.tsx` → `EmailEmbed`, `EmbedTypeCodeAndPreviewDialogContent`
- `apps/web/modules/schedules/hooks/useEvent.ts` → `useEvent`, `useScheduleForEvent`
- `apps/web/modules/users/components/UserTable/EditSheet/EditUserSheet.tsx` → `EditUserSheet`
- `packages/features/bookings/Booker/BookerStoreProvider.tsx` → `useBookerStoreContext`, `useInitializeBookerStoreContext`
- `packages/features/bookings/Booker/hooks/useBookerLayout.ts` → `useBookerLayout`
- `packages/features/bookings/Booker/hooks/useBookerTime.ts` → `useBookerTime`
- `packages/features/bookings/Booker/store.ts` → `createBookerStore`
- `packages/features/bookings/components/Header.tsx` → `Header`
- `packages/features/calendars/components/DatePicker.tsx` → `Days`
- `packages/features/calendars/weeklyview/state/store.ts` → `createCalendarStore`, `useCalendarStore`
- `packages/features/schedules/hooks/useTimesForSchedule.ts` → `useTimesForSchedule`
- `packages/features/troubleshooter/components/EventTypeSelectComponent.tsx` → `EventTypeSelectComponent`
- `packages/platform/atoms/booker/BookerPlatformWrapper.tsx` → `BookerPlatformWrapperComponent`
- `packages/platform/atoms/calendar-view/EventTypeCalendarViewComponent.tsx` → `EventTypeCalendarViewComponent`
- `packages/platform/atoms/hooks/useSlots.ts` → `useSlots`
Existing test(s) that load `zustand` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx`, `apps/web/modules/bookings/components/DatePicker.test.tsx`, `apps/web/modules/schedules/components/date-override-list.test.tsx`, `packages/features/calendars/__tests__/DatePicker.test.tsx` … (+1 more).
Currently-unexercised functions in `zustand` (context only — chainstrip removes these; do NOT write tests to reach them): `checkIfSnapshotChanged`, `destroy`, `error`, `getInitialState`, `h`, `identity`, `is`, `p`, `printWarning`, `q`, `r`, `react` … (+4 more).

### 75. `@vercel/functions` — CLASSIFY 6KB — 6KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/auth/lib/getServerSession.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (7 fns, 6KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/auth/lib/next-auth-options.ts` → `signIn`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `@vercel/functions` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `packages/features/auth/lib/getServerSession.test.ts`, `packages/features/auth/lib/identityProviders.test.ts`, `packages/features/auth/lib/next-auth-options.test.ts`, `packages/features/auth/lib/oAuthAuthorization.test.ts`, `packages/features/auth/lib/outlook.test.ts` … (+1 more).
Currently-unexercised functions in `@vercel/functions` (context only — chainstrip removes these; do NOT write tests to reach them): `CITY_HEADER_NAME`, `COUNTRY_HEADER_NAME`, `EMOJI_FLAG_UNICODE_STARTING_POSITION`, `IP_HEADER_NAME`, `LATITUDE_HEADER_NAME`, `LONGITUDE_HEADER_NAME`, `REGION_HEADER_NAME`, `REQUEST_ID_HEADER_NAME`, `SYMBOL_FOR_REQ_CONTEXT`, `geolocation`, `get`, `getContext` … (+6 more).

### 76. `@radix-ui/react-toggle-group` — CLASSIFY 5KB — 5KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/form/checkbox/Checkbox.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (14 fns, 5KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/form/toggleGroup/BooleanToggleGroup.tsx` → `BooleanToggleGroup2`
- `packages/ui/components/form/toggleGroup/ToggleGroup.tsx` → `(anonymous)`, `ToggleGroup`
Existing test(s) that load `@radix-ui/react-toggle-group` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+6 more).
Currently-unexercised functions in `@radix-ui/react-toggle-group` (context only — chainstrip removes these; do NOT write tests to reach them): `$d7bdfb9eb0fdf311$var$getDirectionAwareKey`, `$d7bdfb9eb0fdf311$var$getFocusIntent`, `$d7bdfb9eb0fdf311$var$wrapArray`, `onPressedChange`.

### 77. `@formbricks/api` — CLASSIFY 5KB — 5KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/trpc/server/routers/viewer/admin/lockUserAccount.handler.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (15 fns, 5KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/lib/formbricks.ts` → `sendFeedbackFormbricks`
- `packages/trpc/server/routers/viewer/feedback/_router.ts` → `(anonymous)`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `@formbricks/api` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `packages/lib/CalEventParser.test.ts`, `packages/lib/CalendarService.test.ts`, `packages/lib/OgImages.test.ts`, `packages/lib/array.test.ts`, `packages/lib/checkRateLimitAndThrowError.test.ts` … (+19 more).
Currently-unexercised functions in `@formbricks/api` (context only — chainstrip removes these; do NOT write tests to reach them): `__defNormalProp`, `__publicField`, `constructor`, `create`, `err`, `makeRequest`, `ok`, `update`, `uploadFile`, `wrapThrowsAsync`.

### 78. `@radix-ui/react-label` — CLASSIFY 5KB — 5KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/form/checkbox/Checkbox.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (9 fns, 2KB)`, `dist/index.module.js (13 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/form/switch/Switch.tsx` → `Switch`
Existing test(s) that load `@radix-ui/react-label` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+6 more).
Currently-unexercised functions in `@radix-ui/react-label` (context only — chainstrip removes these; do NOT write tests to reach them): `_extends`, `composeRefs`, `createContextScope`, `get`, `o`, `onClick`, `onMouseDown`, `r`, `t`, `useComposedRefs`, `useLabelContext`.

### 79. `sonner` — CLASSIFY 5KB — 5KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (25 fns, 5KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/apps/alby/Setup.tsx` → `AlbySetupPage`
- `apps/web/components/apps/applecalendar/Setup.tsx` → `AppleCalendarSetup`
- `apps/web/components/apps/btcpayserver/Setup.tsx` → `BTCPaySetupPage`
- `apps/web/components/apps/caldavcalendar/Setup.tsx` → `CalDavCalendarSetup`
- `apps/web/components/apps/exchange2013calendar/Setup.tsx` → `Exchange2013CalendarSetup`
- `apps/web/components/apps/exchange2016calendar/Setup.tsx` → `Exchange2016CalendarSetup`
- `apps/web/components/apps/exchangecalendar/Setup.tsx` → `ExchangeSetup`
- `apps/web/components/apps/hitpay/Setup.tsx` → `HitPaySetupPage`
- `apps/web/components/apps/ics-feedcalendar/Setup.tsx` → `ICSFeedSetup`
- `apps/web/components/apps/make/Setup.tsx` → `MakeSetup`
- `apps/web/components/apps/paypal/Setup.tsx` → `PayPalSetup`
- `apps/web/components/apps/sendgrid/Setup.tsx` → `SendgridSetup`
- `apps/web/modules/apps/installation/[[...step]]/step-view.tsx` → `OnboardingPage`
- `apps/web/modules/auth/verify-email-change-view.tsx` → `VerifyEmailChange`
- `apps/web/modules/bookings/components/Booker.tsx` → `BookerComponent`
- `apps/web/modules/bookings/views/bookings-single-view.tsx` → `Success`
- `apps/web/modules/getting-started/[[...step]]/onboarding-view.tsx` → `OnboardingPage`
- `apps/web/modules/onboarding/components/OnboardingLayout.tsx` → `OnboardingLayout`
- `apps/web/modules/shell/Shell.tsx` → `Layout`
- `apps/web/modules/signup-view.tsx` → `Signup`
- `apps/web/modules/users/views/users-public-view.tsx` → `UserPage`
- `packages/ui/components/layout/WizardLayout.tsx` → `WizardLayout`
- `packages/ui/components/toast/ProgressToast.tsx` → `hideProgressToast`, `onClose`, `showProgressToast`
- `packages/ui/components/toast/showToast.tsx` → `onClose`, `showToast`
Existing test(s) that load `sonner` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+7 more).
Currently-unexercised functions in `sonner` (context only — chainstrip removes these; do NOT write tests to reach them): `Oe`, `Yt`, `ce`, `de`, `dismiss`, `error`, `g`, `getActiveToasts`, `info`, `jt`, `loading`, `message` … (+16 more).

### 80. `@stripe/stripe-js` — CLASSIFY 4KB — 4KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/stripepayment/lib/VerificationTokenService.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `pure.js (13 fns, 4KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/stripepayment/lib/client/getStripe.ts` → `getStripe`
Currently-unexercised functions in `@stripe/stripe-js` (context only — chainstrip removes these; do NOT write tests to reach them): `_typeof`, `findScript`, `initStripe`, `injectScript`, `loadScript`, `loadStripe`, `registerWrapper`, `setLoadParameters`, `validateLoadParams`.

### 81. `botid` — CLASSIFY 4KB — 4KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/bot-detection/BotDetectionService.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/server/index.mjs (7 fns, 3KB)`, `dist/next/config/index.js (2 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/bot-detection/BotDetectionService.ts` → `checkBotDetection`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `botid` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `apps/web/proxy.test.ts`, `packages/features/bot-detection/BotDetectionService.test.ts`.
Currently-unexercised functions in `botid` (context only — chainstrip removes these; do NOT write tests to reach them): `C`, `H`, `T`, `g`, `h`, `i`, `l`, `m`, `n`, `o`, `w`, `x` … (+2 more).

### 82. `@otplib/core` — CLASSIFY 4KB — 4KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/lib/CalEventParser.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (28 fns, 4KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/lib/totp.ts` → `totpAuthenticatorCheck`, `totpRawCheck`
Existing test(s) that load `@otplib/core` but don't reach the functions above — **extend these**: `apps/web/pages/api/book/recurring-event.test.ts`, `packages/features/bookings/lib/handleNewBooking/global-booking-limits.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/booking-flags.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/booking-limits.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/buildDryRunBooking.test.ts` … (+11 more).
Currently-unexercised functions in `@otplib/core` (context only — chainstrip removes these; do NOT write tests to reach them): `allOptions`, `authenticatorEncoder`, `authenticatorGenerateSecret`, `authenticatorToken`, `check`, `checkDelta`, `clone`, `create`, `createDigestPlaceholder`, `decode`, `encode`, `generate` … (+20 more).

### 83. `next-themes` — CLASSIFY 3KB — 3KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `apps/web/app/WithEmbedSSR.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (5 fns, 3KB)`, `dist/index.module.js (2 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/app/(use-page-wrapper)/refer/DubReferralsPage.tsx` → `DubReferralsPage`
- `apps/web/lib/app-providers-app-dir.tsx` → `CalcomThemeProvider`
- `apps/web/lib/app-providers.tsx` → `CalcomThemeProvider`
- `packages/lib/hooks/useTheme.ts` → `useTheme`
Existing test(s) that load `next-themes` but don't reach the functions above — **extend these**: `apps/web/modules/users/views/users-public-view.test.tsx`.
Currently-unexercised functions in `next-themes` (context only — chainstrip removes these; do NOT write tests to reach them): `ThemeProvider`, `c`, `d`, `e`, `g`, `i`, `setTheme`, `u`.

### 84. `@googleapis/oauth2` — CLASSIFY 3KB — 3KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/_utils/oauth/OAuthManager.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `build/index.js (6 fns, 3KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/_utils/oauth/updateProfilePhotoGoogle.ts` → `updateProfilePhotoGoogle`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `@googleapis/oauth2` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `packages/app-store/_utils/oauth/OAuthManager.test.ts`, `packages/app-store/_utils/oauth/updateProfilePhotoMicrosoft.test.ts`.
Currently-unexercised functions in `@googleapis/oauth2` (context only — chainstrip removes these; do NOT write tests to reach them): `constructor`, `get`, `oauth2`, `tokeninfo`.

### 85. `@testing-library/react` — CLASSIFY 2KB — 2KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/form-builder/useShouldBeDisabledDueToPrefill.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (14 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/test-setup.ts` → `(anonymous)`
- `packages/features/form-builder/testUtils.ts` → `(anonymous)`, `addOption`, `close`, `deleteField`, `fillInFieldIdentifier`, `fillInFieldLabel`, `fillInOption`, `fillInPrice`, `getEditDialogForm`, `getFieldDomElementInTheList`, `getFieldInTheList`, `makeFieldOptional`, `makeFieldRequired`, `openAddFieldDialog`, `openEditFieldDialog`, `openFieldTypeDropdown`, `queryAllOptions`, `queryFieldDomElementInTheList`, `queryOptionForFieldType`, `saveField`, `selectFieldType`, `toHavePriceField`, `toggleField`, `verifyFieldAddition`, `verifyFieldDeletion`, `verifyFieldToggle`, `verifyIdentifierChange`, `verifyOptionPrices`, `verifyThatFieldCanBeMarkedOptional`
- `packages/ui/components/test-setup.tsx` → `(anonymous)`
Existing test(s) that load `@testing-library/react` but don't reach the functions above — **extend these**: `apps/web/components/apps/InstallAppButtonChild.test.tsx`, `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx` … (+50 more).
Currently-unexercised functions in `@testing-library/react` (context only — chainstrip removes these; do NOT write tests to reach them): `asFragment`, `blur`, `configure`, `createLegacyRoot`, `debug`, `fireEvent$1`, `focus`, `hydrate`, `mouseEnter`, `mouseLeave`, `pointerEnter`, `pointerLeave` … (+3 more).

### 86. `@radix-ui/react-switch` — CLASSIFY 2KB — 2KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/form/checkbox/Checkbox.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (8 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/platform/atoms/src/components/ui/switch.tsx` → `(anonymous)`
- `packages/ui/components/form/switch/Switch.tsx` → `Switch`
Existing test(s) that load `@radix-ui/react-switch` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+6 more).
Currently-unexercised functions in `@radix-ui/react-switch` (context only — chainstrip removes these; do NOT write tests to reach them): `createScope`, `useComposedScopes`, `useScope`.

### 87. `react-colorful` — CLASSIFY 2KB — 2KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/form/color-picker/colorpicker.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (14 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/form/color-picker/colorpicker.tsx` → `ColorPicker`
Existing test(s) that load `react-colorful` but don't reach the functions above — **extend these**: `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/event-types/components/tabs/advanced/FormBuilder.test.tsx`, `apps/web/modules/form-builder/components/FormBuilderField.test.tsx` … (+7 more).
Currently-unexercised functions in `react-colorful` (context only — chainstrip removes these; do NOT write tests to reach them): `Ce`, `D`, `E`, `G`, `H`, `He`, `I`, `K`, `N`, `Ne`, `O`, `_e` … (+23 more).

### 88. `@radix-ui/react-avatar` — CLASSIFY 2KB — 2KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/avatar/UserAvatar.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (7 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/avatar/Avatar.tsx` → `Avatar`
Existing test(s) that load `@radix-ui/react-avatar` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/components/Booker.test.tsx`, `apps/web/modules/users/views/users-public-view.test.tsx`, `packages/ui/components/avatar/UserAvatar.test.tsx`, `packages/ui/components/navigation/tabs/navigation.test.tsx`.
Currently-unexercised functions in `@radix-ui/react-avatar` (context only — chainstrip removes these; do NOT write tests to reach them): `createScope`, `useComposedScopes`, `useScope`.

### 89. `cmdk` — CLASSIFY 2KB — 2KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/ui/components/TokenHandler/token-handler.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (13 fns, 2KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/ui/components/command/Command.tsx` → `(anonymous)`
Existing test(s) that load `cmdk` but don't reach the functions above — **extend these**: `apps/web/modules/data-table/components/filters/ColumnVisibilityButton.test.tsx`.
Currently-unexercised functions in `cmdk` (context only — chainstrip removes these; do NOT write tests to reach them): `$`, `CommandDialog`, `CommandEmpty`, `CommandGroup`, `CommandInput`, `CommandItem`, `CommandList`, `CommandLoading`, `CommandRoot`, `CommandSeparator`, `He`, `N` … (+9 more).

### 90. `accept-language-parser` — CLASSIFY 1KB — 1KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/auth/lib/getServerSession.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (1 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/auth/lib/getLocale.ts` → `getLocale`
- `packages/features/auth/lib/getLocaleFromRequest.ts` → `getLocaleFromRequest`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `accept-language-parser` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `packages/features/auth/lib/getServerSession.test.ts`, `packages/features/auth/lib/identityProviders.test.ts`, `packages/features/auth/lib/next-auth-options.test.ts`, `packages/features/auth/lib/oAuthAuthorization.test.ts`, `packages/features/auth/lib/outlook.test.ts` … (+1 more).
Currently-unexercised functions in `accept-language-parser` (context only — chainstrip removes these; do NOT write tests to reach them): `isString`, `pick`.

### 91. `windows-iana` — CLASSIFY 1KB — 1KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/app-store/BookingPageTagManager.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (6 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/app-store/office365calendar/lib/CalendarService.ts` → `getMainTimeZone`
Existing test(s) that load `windows-iana` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `apps/web/pages/api/book/recurring-event.test.ts`, `packages/features/availability/lib/calculateHolidayBlockedDates.test.ts`, `packages/features/bookings/lib/EventManager.test.ts` … (+19 more).
Currently-unexercised functions in `windows-iana` (context only — chainstrip removes these; do NOT write tests to reach them): `findIana`, `findIanaAliases`, `findWindows`, `r`.

### 92. `@otplib/plugin-thirty-two` — CLASSIFY 1KB — 1KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/lib/CalEventParser.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (3 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/lib/totp.ts` → `totpAuthenticatorCheck`
Existing test(s) that load `@otplib/plugin-thirty-two` but don't reach the functions above — **extend these**: `apps/web/pages/api/book/recurring-event.test.ts`, `packages/features/bookings/lib/handleNewBooking/global-booking-limits.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/booking-flags.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/booking-limits.test.ts`, `packages/features/bookings/lib/handleNewBooking/test/buildDryRunBooking.test.ts` … (+11 more).
Currently-unexercised functions in `@otplib/plugin-thirty-two` (context only — chainstrip removes these; do NOT write tests to reach them): `encode`, `keyEncoder`, `quintetCount`.

### 93. `tailwind-merge` — CLASSIFY 1KB — 1KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/platform/atoms/lib/markdownToSafeHTML.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/tailwind-merge.mjs (4 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/coss-ui/src/lib/utils.ts` → `cn`
- `packages/platform/atoms/src/lib/utils.ts` → `cn`
- `packages/ui/classNames.ts` → `classNames`
Existing test(s) that load `tailwind-merge` but don't reach the functions above — **extend these**: `apps/web/components/apps/InstallAppButtonChild.test.tsx`, `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx` … (+34 more).
Currently-unexercised functions in `tailwind-merge` (context only — chainstrip removes these; do NOT write tests to reach them): `extendTailwindMerge`, `get`, `isNever`, `isPercent`, `isUrl`, `mergeConfigs`, `mergePropertyRecursively`, `set`.

### 94. `bcp-47-match` — CLASSIFY 1KB — 1KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/trpc/server/routers/viewer/i18n/i18n.handler.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (2 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/auth/lib/getLocale.ts` → `getLocale`
- `packages/trpc/server/routers/viewer/i18n/i18n.schema.ts` → `(anonymous)`
⚠ You already have test(s) near this dep, but the tracer never saw them LOAD `bcp-47-match` — they were adjacency-guessed, so their green tells us nothing about it. **Fix these** to actually import and exercise it (don't just add a separate test): `packages/features/auth/lib/getServerSession.test.ts`, `packages/features/auth/lib/identityProviders.test.ts`, `packages/features/auth/lib/next-auth-options.test.ts`, `packages/features/auth/lib/oAuthAuthorization.test.ts`, `packages/features/auth/lib/outlook.test.ts` … (+2 more).

### 95. `city-timezones` — CLASSIFY 1KB — 1KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/cityTimezones/cityTimezonesHandler.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (3 fns, 1KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/features/cityTimezones/cityTimezonesHandler.ts` → `cityTimezonesHandler`
Existing test(s) that load `city-timezones` but don't reach the functions above — **extend these**: `packages/features/cityTimezones/cityTimezonesHandler.test.ts`.
Currently-unexercised functions in `city-timezones` (context only — chainstrip removes these; do NOT write tests to reach them): `findFromCityStateProvince`, `findPartialMatch`, `lookupViaCity`.

### 96. `@radix-ui/react-slot` — CLASSIFY 0KB — 0KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `packages/platform/atoms/lib/markdownToSafeHTML.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.mjs (3 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/platform/atoms/src/components/ui/button.tsx` → `(anonymous)`
- `packages/ui/components/section/section.tsx` → `Description`, `Title`
Existing test(s) that load `@radix-ui/react-slot` but don't reach the functions above — **extend these**: `apps/web/components/apps/InstallAppButtonChild.test.tsx`, `apps/web/components/booking/__tests__/CancelBooking.cancellationFee.test.tsx`, `apps/web/components/dialog/__tests__/EditLocationDialog.test.tsx`, `apps/web/modules/apps/components/appCard.test.tsx`, `apps/web/modules/bookings/components/Booker.test.tsx` … (+25 more).
Currently-unexercised functions in `@radix-ui/react-slot` (context only — chainstrip removes these; do NOT write tests to reach them): `Slottable`, `propName`.

### 97. `short-uuid` — CLASSIFY 0KB — 0KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
Runner evidence: `packages/features/bookings/lib/handleSeats/test/handleSeats.test.ts` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `index.js (2 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `packages/emails/lib/getICalUID.ts` → `getICalUID`
- `packages/features/bookings/lib/handleSeats/create/createNewSeat.ts` → `addSeatToBooking`
- `packages/features/bookings/lib/handleSeats/reschedule/owner/combineTwoSeatedBookings.ts` → `combineTwoSeatedBookings`
- `packages/features/bookings/lib/service/RegularBookingService.ts` → `handler`
- `packages/lib/generateHashedLink.ts` → `generateHashedLink`
Existing test(s) that load `short-uuid` but don't reach the functions above — **extend these**: `apps/web/app/api/cron/calendar-subscriptions/__tests__/route.test.ts`, `apps/web/app/api/webhooks/calendar-subscription/[provider]/__tests__/route.test.ts`, `apps/web/lib/daily-webhook/tests/recorded-daily-video.test.ts`, `apps/web/modules/users/views/users-public-view.test.tsx`, `apps/web/pages/api/book/recurring-event.test.ts` … (+53 more).
Currently-unexercised functions in `short-uuid` (context only — chainstrip removes these; do NOT write tests to reach them): `enlargeUUID`, `generate`, `toUUID`.

### 98. `react-turnstile` — CLASSIFY 0KB — 0KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/signup-view.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (2 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/auth/components/Turnstile.tsx` → `TurnstileWidget`
Existing test(s) that load `react-turnstile` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/components/Booker.test.tsx`.
Currently-unexercised functions in `react-turnstile` (context only — chainstrip removes these; do NOT write tests to reach them): `TURNSTILE_LOAD_FUNCTION`, `Turnstile`, `after-interactive-callback`, `before-interactive-callback`, `callback`, `createBoundTurnstileObject`, `ensureTurnstile`, `error-callback`, `execute`, `expired-callback`, `get`, `getResponse` … (+5 more).

### 99. `react-digit-input` — CLASSIFY 0KB — 0KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `lib/index.js (5 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/components/auth/TwoFactor.tsx` → `TwoFactor`
- `apps/web/modules/bookings/components/VerifyCodeDialog.tsx` → `VerifyCodeDialog`
Existing test(s) that load `react-digit-input` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/components/Booker.test.tsx`.
Currently-unexercised functions in `react-digit-input` (context only — chainstrip removes these; do NOT write tests to reach them): `onClick`.

### 100. `react-sticky-box` — CLASSIFY 0KB — 0KB of functions are REACHABLE from your code's imports but never executed by any test, so covtrim holds them un-stubbed (the default disposition). A test exercising those paths converts unknown risk into truth: functions it executes are proven LIVE (correctly kept — a false-dead averted); what stays unexecuted stays held. This buys SAFETY and classification, not bytes — held bytes are removed by reachability precision, not by tests. (Reachability is lexical + conservative: if you are confident these paths cannot run in production, say so in your report instead of forcing a test.)
⚠ **Flake risk:** every call site is a React component/hook file — timing-flaky tests DESTROY existing eliminations; take this only if you can await real async and pin time (no settle-waits).
Runner evidence: `apps/web/modules/bookings/components/BookingDetailsSheet.test.tsx` already runs under vitest near these call sites — a test placed alongside it WILL be picked up. Do not assume a workspace exclusion without verifying.
Held functions live in: `dist/index.js (1 fns, 0KB)` — if existing tests look like they cover this dep, the at-risk surface is in THESE files, not the ones they touch.
Your call sites to test (write/extend tests for these functions):
- `apps/web/modules/bookings/components/Booker.tsx` → `BookerComponent`
Existing test(s) that load `react-sticky-box` but don't reach the functions above — **extend these**: `apps/web/modules/bookings/components/Booker.test.tsx`.
Currently-unexercised functions in `react-sticky-box` (context only — chainstrip removes these; do NOT write tests to reach them): `emptyHandler`, `handler`.

## Recommended skips — reasons given; override only with good cause
32 dep(s) we recommend NOT writing unit tests for. Each lists why — if you
disagree (e.g. you can add a test under the right runner, or an e2e), go ahead;
otherwise leave them: they are covered by the production-build oracle + pinning.

- `nodemailer` (~173KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/emails/templates/_base-email.ts`, `packages/features/auth/lib/sendVerificationRequest.ts`, `packages/lib/serverConfig.ts`
- `markdown-it` (~30KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/web/lib/video/[uid]/getServerSideProps.ts`, `packages/lib/markdownIt.ts`
- `@lingo.dev/_spec` (~1.6MB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/lib/server/service/lingoDotDev.ts`
- `satori` (~1.5MB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/web/app/api/social/og/image/route.tsx`
- `@snaplet/copycat` (~1.4MB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `.snaplet/transform.ts`
- `@base-ui/react` (~411KB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `packages/coss-ui/src/components/accordion.tsx`, `packages/coss-ui/src/components/alert-dialog.tsx`, `packages/coss-ui/src/components/autocomplete.tsx`, `packages/coss-ui/src/components/avatar.tsx` …
- `@ewsjs/xhr` (~373KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/app-store/exchangecalendar/lib/CalendarService.ts`
- `glob` (~149KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/web/pagesAndRewritePaths.ts`
- `@testing-library/jest-dom` (~111KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/web/modules/test-setup.ts`, `packages/app-store/test-setup.ts`, `packages/ui/components/test-setup.tsx`
- `luxon` (~96KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/api/v2/src/modules/api-keys/services/api-keys.service.ts`, `apps/api/v2/src/modules/oauth-clients/services/oauth-flow.service.ts`, `apps/api/v2/src/modules/slots/slots-2024-04-15/services/slots-output.service.ts`, `apps/api/v2/src/modules/slots/slots-2024-04-15/slots.repository.ts` …
- `@lexical/table` (~87KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/ui/components/editor/Editor.tsx`
- `node-html-parser` (~72KB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `packages/testing/src/lib/bookingScenario/expects.ts`
- `pg` (~61KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/api/v2/src/modules/kysely/kysely-read.service.ts`, `apps/api/v2/src/modules/kysely/kysely-write.service.ts`, `apps/api/v2/src/modules/prisma/prisma-read.service.ts`, `apps/api/v2/src/modules/prisma/prisma-write.service.ts` …
- `lru-cache` (~47KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/features/auth/lib/getServerSession.ts`
- `helmet` (~43KB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `apps/api/v2/src/bootstrap.ts`
- `@nestjs/testing` (~41KB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `apps/api/v2/src/app.e2e-spec.ts`, `apps/api/v2/src/modules/auth/oauth2/controllers/atoms-oauth2.controller.e2e-spec.ts`, `apps/api/v2/src/modules/auth/oauth2/controllers/oauth2.controller.e2e-spec.ts`, `apps/api/v2/src/modules/auth/strategies/api-auth/api-auth.strategy.e2e-spec.ts` …
- `@nestjs/config` (~41KB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `apps/api/v2/src/app.module.ts`, `apps/api/v2/src/main.ts`, `apps/api/v2/src/modules/api-keys/services/api-keys.service.ts`, `apps/api/v2/src/modules/apps/apps.module.ts` …
- `@nestjs/throttler` (~30KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/api/v2/src/app.module.ts`, `apps/api/v2/src/lib/throttler-guard.ts`
- `@nest-lab/throttler-storage-redis` (~26KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/api/v2/src/app.module.ts`, `apps/api/v2/src/lib/throttler-guard.ts`
- `nest-winston` (~23KB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `apps/api/v2/src/main.ts`
- `@nestjs/mapped-types` (~17KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/api/v2/src/modules/users/inputs/update-user.input.ts`
- `supertest` (~16KB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `apps/api/v2/src/app.e2e-spec.ts`, `apps/api/v2/src/modules/auth/oauth2/controllers/atoms-oauth2.controller.e2e-spec.ts`, `apps/api/v2/src/modules/auth/oauth2/controllers/oauth2.controller.e2e-spec.ts`, `apps/api/v2/src/modules/conferencing/controllers/conferencing.controller.e2e-spec.ts` …
- `@prisma/generator-helper` (~15KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/prisma/enum-generator.ts`
- `@nestjs/axios` (~14KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/api/v2/src/modules/conferencing/conferencing.module.ts`, `apps/api/v2/src/modules/conferencing/controllers/conferencing.controller.ts`, `apps/api/v2/src/modules/stripe/controllers/stripe.controller.ts`, `apps/api/v2/src/modules/stripe/stripe.module.ts`
- `schema-dts` (~13KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/web/components/schemas/EventReservationSchema.tsx`
- `@trpc/next` (~9KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/trpc/react/trpc.ts`
- `cookie-parser` (~8KB) — skip because every importer sits outside vitest's scope (no traced test file lives in those packages) — a unit test here can't load it via the sanctioned runner. Coverable only with that package's own runner or an e2e.
  imported at: `apps/api/v2/src/bootstrap.ts`
- `resize-observer-polyfill` (~6KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/web/modules/test-setup.ts`
- `dayjs` (~5KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/web/modules/data-table/components/filters/DateRangeFilter.tsx`, `apps/web/modules/event-types/components/tabs/advanced/RequiresConfirmationController.tsx`, `apps/web/modules/settings/components/TimezoneChangeDialog.tsx`, `packages/dayjs/index.ts` …
- `class-variance-authority` (~1KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `apps/web/modules/calendars/weeklyview/components/event/Event.tsx`, `packages/coss-ui/src/components/alert.tsx`, `packages/coss-ui/src/components/badge.tsx`, `packages/coss-ui/src/components/button.tsx` …
- `@evyweb/ioctopus` (~1KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/features/di/di.ts`, `packages/features/di/modules/FeatureOptInService.ts`, `packages/features/di/modules/TranslationService.ts`, `packages/features/di/shared/services/logger.service.ts` …
- `vitest-fetch-mock` (~1KB) — skip because it has no plain function call site — only module-scope/DI/decorator wiring imports it, so a unit test can't exercise it in isolation. An e2e/integration test could; meanwhile the production-build oracle + pinning cover it.
  imported at: `packages/testing/src/lib/bookingScenario/bookingScenario.ts`, `packages/testing/src/lib/bookingScenario/expects.ts`, `packages/testing/src/lib/bookingScenario/MockPaymentService.ts`

## When done
Run `yarn test` until green, then re-run `chainstrip coverage` — the covered
percentages should rise and chainstrip can trim/eliminate more of those dependencies.

_Generated by `chainstrip coverage --prompt` at 2026-07-29T21:49:40.055Z. Worklist is prioritised: live-CVE deps first, then least-covered._

And the probe path's paper trail: the batch prompt witness emitted, and the model's reply as it was ingested for grading — probes targeting the app's own call paths, including one target the model declined as unreachable in principle, reasoning attached:

.chainstrip/probes/campaign-batch-1-prompt.md — the witness batch prompt of the 2026-07-20 campaign, in full (scroll inside)
# Evidence probes for cal.diy

You are writing EVIDENCE PROBES, not unit tests. Each probe tries to make the APPLICATION execute a target it has never executed under any test. A probe is graded by coverage: it is kept if and only if it passes, is deterministic, and the target actually runs. Style, elegance and assertions are irrelevant.

## The two rules (violating either destroys the evidence)

1. **Go through the application, never the dependency.** Import the app's own modules (the call paths listed per target) and drive THEM. Importing the dependency and calling the target directly proves nothing — every function on npm is callable.
2. **Stay inside what the deployed app could plausibly encounter.** No hostile fuzzing, no impossible configs — an out-of-contract probe "proves alive" code no real deployment reaches. Fault injection IS in-contract for error-handling targets (marked `airbag`): malformed feeds, garbage user input, failing fetches happen in production. A probe may stub network boundaries (e.g. fetch) if the payload is realistic; note that judgment in a comment.

Practical notes: probe files execute from `.chainstrip-probes/`, one directory below the repo root — import app modules by relative path with a `../` prefix (`await import("../packages/lib/foo")`; a `./packages/...` path resolves inside the probe dir and fails). Modules that read env at import time need the env stubbed BEFORE a dynamic import (a static import races the stub). Prefer dynamic `await import(...)` inside the test body.

## Probe skeleton (vitest)

```ts
import { test, expect } from "vitest";

test("probe", async () => {
  // import APP modules (never the dependency directly) and drive them
  expect(true).toBe(true);
});
```

## Targets

### dep:rxjs
Dependency `rxjs` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ./operators.

App-side call paths (import THESE):
- `apps/api/v2/src/middleware/request-ids/request-id.interceptor.ts` — imports { tap } from subpaths ./operators

  ```
  …
  3: import { Request, Response } from "express";
  4: import { tap } from "rxjs/operators";
  5: 
  …
  21:     return next.handle().pipe(
  22:       tap((data) => {
  23:         const { statusCode } = response;
  ```

### dep:satori
Dependency `satori` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `apps/web/app/api/social/og/image/route.tsx` — imports { SatoriOptions }

  ```
  …
  2: import type { NextRequest } from "next/server";
  3: import type { SatoriOptions } from "satori";
  4: import { z, ZodError } from "zod";
  …
  44: 
  45:     const fonts: SatoriOptions["fonts"] = [];
  46: 
  ```

### dep:schema-dts
Dependency `schema-dts` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `apps/web/components/schemas/EventReservationSchema.tsx` — imports { EventReservation, Person, ReservationStatusType }

  ```
  …
  3: import { JsonLd } from "react-schemaorg";
  4: import type { EventReservation, Person, ReservationStatusType } from "schema-dts";
  5: 
  …
  33: }) => {
  34:   const reservationStatus = useMemo<ReservationStatusType>(() => {
  35:     switch (status) {
  …
  48:   return (
  49:     <JsonLd<EventReservation>
  50:       item={{
  51:         "@context": "https://schema.org",
  52:         "@type": "EventReservation",
  53:         reservationId,
  ```

### dep:svix
Dependency `svix` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `packages/app-store/alby/lib/parseInvoice.ts` — imports { Webhook }

  ```
  …
  1: import type { Invoice } from "@getalby/sdk/dist/types";
  2: import { Webhook } from "svix";
  3: 
  …
  6:   headers: {
  7:     "svix-id": string;
  8:     "svix-timestamp": string;
  9:     "svix-signature": string;
  10:   },
  …
  13:   try {
  14:     const wh = new Webhook(webhookEndpointSecret);
  15:     return wh.verify(body, headers) as Invoice;
  ```

### dep:@snaplet/copycat
Dependency `@snaplet/copycat` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `.snaplet/transform.ts` — imports { copycat }

  ```
  …
  3: // This config was generated by Snaplet make sure to check it over before using it.
  4: import { copycat as c } from "@snaplet/copycat";
  5: import { defineConfig } from "snaplet";
  ```

### dep:kbar
Dependency `kbar` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `apps/web/modules/shell/Kbar.tsx` — imports { Action, KBarAnimator, KBarPortal, KBarPositioner, KBarProvider, KBarResults, KBarSearch, useKBar, useMatches, useRegisterActions }

  ```
  …
  16: } from "@coss/ui/icons";
  17: import type { Action } from "kbar";
  18: import {
  19:   KBarAnimator,
  20:   KBarPortal,
  21:   KBarPositioner,
  22:   KBarProvider,
  23:   KBarResults,
  24:   KBarSearch,
  25:   useKBar,
  26:   useMatches,
  27:   useRegisterActions,
  ```

### dep:ioredis
Dependency `ioredis` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `apps/api/v2/src/modules/redis/redis.service.ts` — imports { Redis }

  ```
  …
  3: import { ConfigService } from "@nestjs/config";
  4: import { Redis } from "ioredis";
  5: 
  …
  7: export class RedisService implements OnModuleDestroy {
  8:   public redis: Redis;
  9:   private readonly logger = new Logger("RedisService");
  …
  13:     const dbUrl = configService.get<string>("db.redisUrl", { infer: true });
  14:     if (!dbUrl) throw new Error("Misconfigured Redis, halting.");
  15: 
  16:     this.redis = new Redis(dbUrl);
  17: 
  ```

### dep:@stripe/stripe-js
Dependency `@stripe/stripe-js` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ., ./pure.

App-side call paths (import THESE):
- `packages/app-store/stripepayment/lib/client/getStripe.ts` — imports { Stripe, loadStripe } from subpaths ., ./pure

  ```
  …
  1: import type { Stripe } from "@stripe/stripe-js";
  2: import { loadStripe } from "@stripe/stripe-js/pure";
  3: 
  …
  6: const stripePublicKey = process.env.NEXT_PUBLIC_STRIPE_PUBLIC_KEY || "";
  7: let stripePromise: Promise<Stripe | null>;
  8: 
  9: /**
  10:  * This is a singleton to ensure we only instantiate Stripe once.
  11:  */
  …
  13:   if (!stripePromise) {
  14:     stripePromise = loadStripe(
  15:       userPublicKey || stripePublicKey /* , {
  ```

### dep:next-seo
Dependency `next-seo` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `apps/web/components/PageWrapper.tsx` — imports { DefaultSeo }

  ```
  …
  11: 
  12: import { DefaultSeo } from "next-seo";
  13: import { Inter } from "next/font/google";
  …
  20: import { getCalcomUrl } from "@calcom/lib/getCalcomUrl";
  21: import { buildCanonical } from "@calcom/lib/next-seo.config";
  22: import { IconSprites } from "@calcom/ui/components/icon";
  …
  25: import AppProviders from "@lib/app-providers";
  26: import { seoConfig } from "@lib/config/next-seo.config";
  27: 
  …
  71:       </Head>
  72:       <DefaultSeo
  73:         // Set canonical to https://cal.com or self-hosted URL
  ```
- `packages/ui/components/test-setup.tsx`

  ```
  …
  20: // Add new mocks
  21: vi.mock("next-seo", () => ({
  22:   NextSeo: () => null,
  ```

### dep:city-timezones
Dependency `city-timezones` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `packages/features/cityTimezones/cityTimezonesHandler.ts` — imports { cityMapping }

  ```
  …
  1: import { cityMapping as allCities } from "city-timezones";
  2: 
  ```

### dep:react-easy-crop
Dependency `react-easy-crop` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `packages/ui/components/image-uploader/BannerUploader.tsx`

  ```
  …
  3: import { useCallback, useState, useEffect } from "react";
  4: import Cropper from "react-easy-crop";
  5: 
  ```
- `packages/ui/components/image-uploader/ImageUploader.tsx`

  ```
  …
  3: import { useCallback, useState } from "react";
  4: import Cropper from "react-easy-crop";
  5: 
  ```

### dep:qs
Dependency `qs` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `apps/api/v2/src/main.ts`

  ```
  …
  9: import { WinstonModule } from "nest-winston";
  10: import qs from "qs";
  11: import { TRIGGER_VERSION } from "../trigger.version";
  …
  92:       if (queryString) {
  93:         req.query = qs.parse(queryString, { arrayLimit: 1000 });
  94:       }
  …
  118:   // Custom query parser configuration for the underlying Express app
  119:   app.set("query parser", (str: string) => qs.parse(str, { arrayLimit: 1000 }));
  120: 
  ```
- `apps/web/components/apps/hitpay/HitpayPaymentComponent.tsx`

  ```
  …
  3: import { useRouter } from "next/navigation";
  4: import qs from "qs";
  5: import { useEffect, useRef } from "react";
  …
  83: 
  84:         const query = qs.stringify(queryParams);
  85:         const url = `/booking/${parsedData.data.bookingUid}?${query}`;
  ```
- `packages/app-store/hitpay/api/callback.ts`

  ```
  …
  1: import type { NextApiRequest, NextApiResponse } from "next";
  2: import qs from "qs";
  3: import { z } from "zod";
  …
  94: 
  95:   const query = qs.stringify(queryParams);
  96:   const url = `/booking/${payment.booking.uid}?${query}`;
  ```
- `packages/app-store/hitpay/lib/PaymentService.ts`

  ```
  …
  1: import axios from "axios";
  2: import qs from "qs";
  3: import { v4 as uuidv4 } from "uuid";
  …
  119: 
  120:       const response = await axios.post(requestUrl, qs.stringify(formData), {
  121:         headers: {
  ```
- `packages/app-store/zoho-bigin/api/callback.ts`

  ```
  …
  2: import type { NextApiRequest, NextApiResponse } from "next";
  3: import qs from "qs";
  4: 
  …
  70: 
  71:   const tokenInfo = await axios.post(accountsUrl, qs.stringify(formData), {
  72:     headers: {
  ```

### dep:@nestjs/throttler
Dependency `@nestjs/throttler` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `apps/api/v2/src/app.module.ts` — imports { seconds, ThrottlerModule }

  ```
  …
  5: import { APP_FILTER, APP_GUARD, APP_INTERCEPTOR } from "@nestjs/core";
  6: import { seconds, ThrottlerModule } from "@nestjs/throttler";
  7: import { SentryGlobalFilter, SentryModule } from "@sentry/nestjs/setup";
  …
  39:     }),
  40:     ThrottlerModule.forRootAsync({
  41:       imports: [RedisModule],
  …
  44:         // note(Lauris): IMPORTANT: rate limiting is enforced by CustomThrottlerGuard, but we need to have at least one
  45:         // entry in the throttlers array otherwise CustomThrottlerGuard is not invoked at all. If we specify only ThrottlerModule
  46:         // without .forRootAsync then throttler options are not passed to CustomThrottlerGuard containing redis connection etc.
  …
  50:             name: "dummy",
  51:             ttl: seconds(60),
  52:             limit: 120,
  ```
- `apps/api/v2/src/lib/throttler-guard.ts` — imports { ThrottlerGuard, ThrottlerException, ThrottlerRequest, ThrottlerModuleOptions }

  ```
  …
  8: import {
  9:   ThrottlerGuard,
  10:   ThrottlerException,
  11:   ThrottlerRequest,
  12:   ThrottlerModuleOptions,
  13: } from "@nestjs/throttler";
  14: import { Request, Response } from "express";
  …
  30: @Injectable()
  31: export class CustomThrottlerGuard extends ThrottlerGuard {
  32:   private logger = new Logger("CustomThrottlerGuard");
  …
  43:   constructor(
  44:     options: ThrottlerModuleOptions,
  45:     @Inject(ThrottlerStorageRedisService) protected readonly storageService: ThrottlerStorageRedisService,
  ```

### dep:@todesktop/client-core
Dependency `@todesktop/client-core` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `apps/web/pages/_document.tsx` — imports { platform }

  ```
  …
  1: import { platform } from "@todesktop/client-core";
  2: import type { IncomingMessage } from "node:http";
  …
  42:       try {
  43:         return platform.todesktop.isDesktopApp();
  44:       } catch {
  ```

### dep:@stripe/react-stripe-js
Dependency `@stripe/react-stripe-js` is never LOADED by any test (class: build-validated). Goal: make the app load it — import the app modules below and drive the code paths that touch it. Used subpaths: ..

App-side call paths (import THESE):
- `packages/platform/atoms/event-types/payments/StripePaymentForm.tsx` — imports { Elements, useElements, useStripe }

  ```
  …
  3: import { useLocale } from "@calcom/lib/hooks/useLocale";
  4: import { Elements, useElements, useStripe } from "@stripe/react-stripe-js";
  5: import type { SyntheticEvent } from "react";
  …
  14:   const { t } = useLocale();
  15:   const elements = useElements();
  16:   const paymentOption = props.payment.paymentOption;
  17:   const attendeeEmail = props.booking.attendees[0].email;
  18:   const stripe = useStripe();
  19: 
  …
  117:   return (
  118:     <Elements
  119:       stripe={stripePromise}
  ```

## Output format (STRICT — parsed by machine)

For each probe, emit exactly one fenced block. The info string names the target id(s) the probe goes after and a filename:

````
```probe target=<target-id>[,<target-id>...] file=<kebab-name>.probe.test.ts
<probe code>
```
````

One probe may serve several targets of the same dependency. Skip a target you judge unreachable through the app — say why in one line OUTSIDE any fence (that reason is evidence too). No other fenced blocks in the reply.
.chainstrip/probes/campaign-batch-1-reply.md — the model's probes as ingested for grading, 2026-07-20 campaign, in full (scroll inside)
Reasoning note (outside any fence): `dep:schema-dts`'s only call path (`EventReservationSchema.tsx`) imports `EventReservation`, `Person`, `ReservationStatusType` via `import type { ... } from "schema-dts"` — a type-only import that is erased by the TS/esbuild compiler and never causes a runtime `require`/`import` of the `schema-dts` package. Since `schema-dts` itself ships only `.d.ts` declarations with no runtime module, there is no way to make the app "load" it at runtime through this call path (or any call path, since the package has nothing to load). Skipping this target as unreachable in principle, not just in practice.

```probe target=dep:rxjs file=request-id-interceptor.probe.test.ts
import { of } from "rxjs";
import { test, expect } from "vitest";

test("probe", async () => {
  // Go through the app's own interceptor; only use rxjs `of` to build the fake
  // upstream Observable a real Nest CallHandler would provide (test harness only).
  const mod: any = await import(
    "../apps/api/v2/src/middleware/request-ids/request-id.interceptor"
  );
  const InterceptorCtor = Object.values(mod).find(
    (v) => typeof v === "function"
  ) as any;
  expect(InterceptorCtor).toBeTruthy();

  const interceptor = new InterceptorCtor();
  const fakeRequest: any = { headers: {} };
  const fakeResponse: any = { statusCode: 200 };
  const context: any = {
    switchToHttp: () => ({
      getRequest: () => fakeRequest,
      getResponse: () => fakeResponse,
    }),
  };
  const next: any = { handle: () => of({ hello: "world" }) };

  const result$ = interceptor.intercept(context, next);
  const emitted: any = await new Promise((resolve, reject) => {
    result$.subscribe({ next: resolve, error: reject });
  });

  expect(emitted).toEqual({ hello: "world" });
});
```

```probe target=dep:satori file=og-image-route.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  // Importing the route already executes its module-level `import satori from "satori"`
  // (the SatoriOptions import in the excerpt is type-only, but the actual satori()
  // call site elsewhere in the file requires a real value import of the package).
  let mod: any;
  try {
    mod = await import("../apps/web/app/api/social/og/image/route");
  } catch (e) {
    mod = e;
  }
  expect(mod).toBeTruthy();

  if (mod && typeof mod.GET === "function") {
    try {
      // realistic query params this route would actually receive in prod
      const req = new Request(
        "https://example.com/api/social/og/image?type=meeting&title=Evidence+Probe"
      );
      await mod.GET(req as any);
    } catch {
      // font/network fetches inside the handler can't complete deterministically
      // in this test env; the satori module was already loaded by the import above.
    }
  }
});
```

```probe target=dep:svix file=parse-invoice.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  const mod: any = await import("../packages/app-store/alby/lib/parseInvoice");
  const parseInvoice = mod.parseInvoice ?? mod.default;
  expect(typeof parseInvoice).toBe("function");

  // realistic-shaped (but fabricated) svix webhook secret/headers, as a real
  // deployment would receive from an untrusted webhook sender (airbag scenario).
  const secret =
    "whsec_" + Buffer.from("0123456789abcdef0123456789abcdef").toString("base64");
  const body = JSON.stringify({ id: "evt_test", type: "invoice.paid" });
  const headers = {
    "svix-id": "msg_test123",
    "svix-timestamp": String(Math.floor(Date.now() / 1000)),
    "svix-signature": "v1,bm90YXJlYWxzaWduYXR1cmU=",
  };

  try {
    await parseInvoice(secret, body, headers);
  } catch {
    // signature verification is expected to fail with a fabricated secret;
    // svix's Webhook class was still constructed and .verify() was executed.
  }
});
```

```probe target=dep:@snaplet/copycat file=snaplet-transform.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  let mod: any;
  try {
    mod = await import("../.snaplet/transform");
  } catch (e) {
    mod = e;
  }
  expect(mod).toBeTruthy();
});
```

```probe target=dep:kbar file=kbar-shell.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  // Kbar.tsx imports KBarAnimator/KBarPortal/etc as real values (not types), so
  // simply loading the module forces the kbar package to load.
  let mod: any;
  try {
    mod = await import("../apps/web/modules/shell/Kbar");
  } catch (e) {
    mod = e;
  }
  expect(mod).toBeTruthy();
});
```

```probe target=dep:ioredis file=redis-service.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  const { RedisService } = await import(
    "../apps/api/v2/src/modules/redis/redis.service"
  );
  const fakeConfigService: any = {
    get: (_key: string) => "redis://127.0.0.1:65535",
  };
  const svc = new RedisService(fakeConfigService);
  // attach an error handler before anything else runs so the inevitable
  // connection failure to a closed port doesn't crash the process
  svc.redis.on("error", () => {});
  expect(svc.redis).toBeTruthy();
  svc.redis.disconnect();
});
```

```probe target=dep:@stripe/stripe-js file=get-stripe.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  const mod: any = await import(
    "../packages/app-store/stripepayment/lib/client/getStripe"
  );
  const getStripe = mod.default ?? mod.getStripe;
  expect(typeof getStripe).toBe("function");

  const promise = getStripe("pk_test_evidenceprobe");
  expect(promise).toBeInstanceOf(Promise);
  // loadStripe() injects a <script src="https://js.stripe.com/..."> tag; it can't
  // complete in this test env, so we don't await it — calling it is enough to
  // exercise the app's real usage of @stripe/stripe-js/pure.
  promise.catch(() => {});
});
```

```probe target=dep:next-seo file=page-wrapper.probe.test.ts
import { vi, test, expect } from "vitest";

// next/font/google requires Next's build-time SWC font loader / network access
// to Google Fonts; stub it so PageWrapper.tsx can be evaluated the same way a
// real Next build would resolve fonts, without hitting the network. This does
// not touch next-seo itself, which is imported (as a real value) earlier in
// the file and thus loads regardless.
vi.mock("next/font/google", () => ({
  Inter: () => ({ className: "inter", variable: "--font-inter" }),
}));

test("probe", async () => {
  let mod: any;
  try {
    mod = await import("../apps/web/components/PageWrapper");
  } catch (e) {
    mod = e;
  }
  expect(mod).toBeTruthy();
});
```

```probe target=dep:city-timezones file=city-timezones-handler.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  const mod: any = await import(
    "../packages/features/cityTimezones/cityTimezonesHandler"
  );
  expect(mod).toBeTruthy();

  const handler = mod.default ?? mod.cityTimezonesHandler;
  if (typeof handler === "function") {
    try {
      await handler({ input: { cityInput: "New York" } } as any);
    } catch {
      // exact trpc procedure shape may differ; the module-level
      // `cityMapping` import from city-timezones already ran on import.
    }
  }
});
```

```probe target=dep:react-easy-crop file=image-uploader.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  let mod: any;
  try {
    mod = await import(
      "../packages/ui/components/image-uploader/ImageUploader"
    );
  } catch (e) {
    mod = e;
  }
  expect(mod).toBeTruthy();
});
```

```probe target=dep:qs file=qs-app-modules.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  // qs is imported as the very first/second statement in each of these files,
  // so it loads before any later, unrelated app-specific code can fail.
  let cbMod: any;
  try {
    cbMod = await import("../packages/app-store/hitpay/api/callback");
  } catch (e) {
    cbMod = e;
  }
  expect(cbMod).toBeTruthy();

  let svcMod: any;
  try {
    svcMod = await import("../packages/app-store/hitpay/lib/PaymentService");
  } catch (e) {
    svcMod = e;
  }
  expect(svcMod).toBeTruthy();
});
```

```probe target=dep:@nestjs/throttler file=custom-throttler-guard.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  let mod: any;
  try {
    mod = await import("../apps/api/v2/src/lib/throttler-guard");
  } catch (e) {
    mod = e;
  }
  expect(mod).toBeTruthy();
});
```

```probe target=dep:@todesktop/client-core file=document-platform.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  let mod: any;
  try {
    mod = await import("../apps/web/pages/_document");
  } catch (e) {
    mod = e;
  }
  expect(mod).toBeTruthy();
});
```

```probe target=dep:@stripe/react-stripe-js file=stripe-payment-form.probe.test.ts
import { test, expect } from "vitest";

test("probe", async () => {
  let mod: any;
  try {
    mod = await import(
      "../packages/platform/atoms/event-types/payments/StripePaymentForm"
    );
  } catch (e) {
    mod = e;
  }
  expect(mod).toBeTruthy();
});
```

What's left

The 48 reached advisories are upgrade work ChainStrip can't do for the team, axios's 27 first among them. The 37 unresolved stay on the books: advisories too coarse to map to a symbol never get a clean bill. The framework class — Next.js and its orbit — ships retained-whole by design: lifecycle-stripped, hash-pinned, update-gated, but present, because framework dynamism can't be safely cut. Thousands of reachable-but-unexecuted functions ship held rather than stubbed, error and retry paths deliberately among them; each hold is listed in the report next to the evidence that would clear it, and the coverage worklist is the queue for closing them.

And the standing caveat: every removal above means proven dead, removed from the artifact, and revalidated by Cal's own build, suite, and served e2e — not "verified safe in production."

Sound like your stack?

These results should transfer if:

Book a demo A 15-minute walkthrough: a live elimination on an open-source tree, plus a rough cut of your own ladder from nothing but your lockfile.