npm run listes -- --fetch downloads ten public sources: OFAC SDN, the OFAC consolidated (non-SDN) lists, the US Consolidated Screening List (its Commerce and State lists), the UN Security Council list, the EU financial sanctions list, the UK Sanctions List, the EU's designated vessels, Australia's DFAT Consolidated List, the Consolidated Canadian Autonomous Sanctions List and New Zealand's Russia Sanctions Register. It writes a manifest, and the manifest is committed to git. The manifest holds the source, the URL, the date, the sha256 (the content hash of the file), the byte and entry counts. The list data itself stays out of the repository. When the tool later reads a list from disk, it recomputes the content hash. Screening against a list other than the recorded one certifies nothing. So the tool refuses a file that no longer matches the manifest and names both content hashes.
OFAC states its own record count inside the file, and on each fetch the tool checks the entries it read against that count. The UN address is the one the Security Council page publishes. Without the --fetch flag, npm run listes reports what is on disk and touches nothing.
Verify without the networkThe no-flag form reads the disk against the manifest and reports that it touched no network.
run it yourself
npm run listesreports date, content hash state and entry counts, with no network touched
Where it livessrc/listes.ts:750 · src/listes.ts:775