Software Passport · public repository

AbsaOSS/cobrix

Observed by SPR on 2026-09-26 at commit 339ddbad9d89b3430731ac2f1a27e5dd9c0605c6 (master). Source: github.com/AbsaOSS/cobrix.

SBOM components30
Open findings18
Critical / high0 / 0
Evidence items34

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
MEDIUMLicense not observedspark-streaming_2.12
MEDIUMLicense not observedspark-sql_2.12
MEDIUMLicense not observedspark-core_2.12
MEDIUMLicense not observedspark-cobol_2.12
MEDIUMLicense not observedslf4j-simple
MEDIUMLicense not observedslf4j-log4j12
MEDIUMLicense not observedslf4j-api
MEDIUMLicense not observedscodec-core_2.12
MEDIUMLicense not observedscalatest_2.12
MEDIUMLicense not observedscalap
MEDIUMLicense not observedscala-library
MEDIUMLicense not observedmockito-core
MEDIUMLicense not observedjackson-module-scala_2.12
MEDIUMLicense not observedjackson-dataformat-xml
MEDIUMLicense not observedjackson-dataformat-csv
MEDIUMLicense not observedbcpg-jdk18on
MEDIUMLicense not observedantlr4-runtime
UNKNOWNMAL-2025-6125slf4j-api@1.7.25

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy