Observed scope: 4 supported text files; 1 unsupported README skipped
Hashes: the downloadable manifest records the complete input SHA-256, PDF SHA-256, and evidence fingerprint.
Findings: 4 distinct risk types · 5 file/line evidence records
Scope limitation: static uploaded-source scan only. No AWS account was queried; resource inventory and runtime behavior are not inferred.
What is inside the PDF
Engine-ranked findings with exact observed file/line evidence
Observed reach, remediation notes, and a configured reference per finding
Explicit scan scope, skipped-file count, limitations, and roll-forward order
The same input hash and evidence fingerprint recorded in the manifest above
What the report does not claim
It does not estimate downtime dollars, count deployed instances/functions, inspect omitted files, or guarantee that a match is reachable at runtime. Those facts require environment-specific validation.