# CS Code Sample Security Review Summary

Product: Airgap Agent  
Release: 1.5.0  
Organisation: Demo Defence Systems  
Review status: Needs review  
Readiness score: 84%

## Summary

Airgap Agent 1.5.0 is a candidate release for restricted Docker Compose deployment. Evidence was generated locally with CS Code CLI. No source code was uploaded to the SaaS dashboard. Uploaded metadata is limited to release summaries, vulnerability counts, SBOM summary, endpoint summary, environment variable names and update-diff summary.

## Key Review Findings

- Critical vulnerabilities: 0
- High vulnerabilities: 0
- Medium vulnerabilities: 1
- SBOM components: 51
- Services detected: 4
- Exposed ports: 3
- Environment variables listed: 10
- Potential external endpoints: 3

## Policy Results

No blocker is present under the default policy. Review is required because the release changes:

- External endpoint references.
- Environment variable names.
- Exposed port mappings.

## Data Handling Statement

The scan ran in the vendor-controlled environment. The evidence pack excludes source code, raw repository contents, secret values, raw vulnerability reports and full file inventories. Optional evidence artefact upload is disabled unless the organisation explicitly allows it.

## Buyer Questions Answered

### What changed since the last release?

The release removes a legacy sync path, adds a local collector service, adds one port and resolves a critical runtime-image vulnerability.

### Are there unresolved severe vulnerabilities?

No critical or high findings are present in the candidate release summary. One medium finding remains and has a fixed-version note.

### Are there new external network dependencies?

One disabled-by-default telemetry placeholder is present and should be reviewed with the buyer. The deployment can operate without enabling it.

### What should be approved before shipment?

The buyer-facing approval should confirm the collector port, retention environment variable and disabled telemetry placeholder are acceptable for the target environment.

## Recommended Decision

Approve after endpoint and port review, or reject if the buyer does not permit disabled telemetry placeholders in configuration files.
