Software Passport · public repository

HeyPuter/puter

Observed by SPR on 2026-09-13 at commit 4a23c296f00ec75cd9f28d172a4b94dfc24a91a8 (main). Source: github.com/HeyPuter/puter.

SBOM components788
Open findings17
Critical / high1 / 3
Evidence items792

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
CRITICALPrivate key material
HIGHGHSA-rgj7-g3m4-5g8csharp@0.35.2
HIGHStatic API key-like configuration
HIGHHard-coded credential assignment
MEDIUMLicense not observedxmlhttprequest-ssl
MEDIUMLicense not observedstreamsearch
MEDIUMLicense not observedputer-mcp-connector
MEDIUMLicense not observeddocs
MEDIUMLicense not observedbusboy
MEDIUMLicense not observed@mistralai/mistralai
MEDIUMLicense not observed@heyputer/worker-types
MEDIUMLicense not observed@heyputer/worker
MEDIUMLicense not observed@heyputer/puter.js
MEDIUMLicense not observed@heyputer/gui
MEDIUMLicense not observed@heyputer/cli
MEDIUMLicense not observed@heyputer/backend
UNKNOWNGHSA-rgwj-5xj2-c3m3mysql2@3.22.6

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy