The Oct 2017 NCC report link on the Security audits page is dead — NCC retired the nccgroup.trust domain, so it's not a 404, the host just doesn't resolve anymore. lychee.toml already excludes that domain under the 4XX FIXME block, which is probably why CI never flagged it.
Report's still up at nccgroup.com though: https://www.nccgroup.com/research/the-update-framework-tuf-security-assessment/ — "The Update Framework (TUF) Security Assessment", dated 19 October 2017. Looks like a one-line swap in audits.md plus removing the dead exclude line in lychee.toml. Direct-PDF-linking is not working — NCC's redirect 403s non-browser requests, so it'd just fail the checker again. Could mirror it under /audits/ instead, like the X41 report.
The Oct 2017 NCC report link on the Security audits page is dead — NCC retired the nccgroup.trust domain, so it's not a 404, the host just doesn't resolve anymore. lychee.toml already excludes that domain under the 4XX FIXME block, which is probably why CI never flagged it.
Report's still up at nccgroup.com though: https://www.nccgroup.com/research/the-update-framework-tuf-security-assessment/ — "The Update Framework (TUF) Security Assessment", dated 19 October 2017. Looks like a one-line swap in audits.md plus removing the dead exclude line in lychee.toml. Direct-PDF-linking is not working — NCC's redirect 403s non-browser requests, so it'd just fail the checker again. Could mirror it under /audits/ instead, like the X41 report.