Illustrative fixture

Dependency update scenarios, with their evidence clearly labelled.

The security rows use package versions, GHSA identifiers, and remediation targets from a repeatable npm audit of the preserved sample lockfile. The major-version rows and all decision labels are illustrative examples, not captured Bivouac analyzer output, actual pull requests, or reported test results.

Loading the illustrative demo ledger…