Software Passport · public repository

KasumiYuku/Aurorix

Observed by SPR on 2026-09-18 at commit 4c0cdd692686e657e6fc25cfeadd875e9ad62350 (main). Source: github.com/KasumiYuku/Aurorix.

SBOM components168
Open findings155
Critical / high0 / 0
Evidence items172

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings (top 25 of 155)

SeverityFindingComponentFixed in
MEDIUMLicense not observedyallist
MEDIUMLicense not observedvitefu
MEDIUMLicense not observedvite-plugin-solid
MEDIUMLicense not observedvite
MEDIUMLicense not observedvanilla-calendar-pro
MEDIUMLicense not observedupdate-browserslist-db
MEDIUMLicense not observedtypescript
MEDIUMLicense not observedtinyglobby
MEDIUMLicense not observedtapable
MEDIUMLicense not observedtailwindcss
MEDIUMLicense not observedsource-map-js
MEDIUMLicense not observedsolid-refresh
MEDIUMLicense not observedsolid-js
MEDIUMLicense not observedseroval-plugins
MEDIUMLicense not observedseroval
MEDIUMLicense not observedsemver
MEDIUMLicense not observedrolldown
MEDIUMLicense not observedpreline
MEDIUMLicense not observedpostcss
MEDIUMLicense not observedpicomatch
MEDIUMLicense not observedpicocolors
MEDIUMLicense not observedparse5
MEDIUMLicense not observednouislider
MEDIUMLicense not observednode-releases
MEDIUMLicense not observednanoid

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy