Software Passport · public repository

KuangjuX/hypocaust

Observed by SPR on 2026-09-19 at commit 5c6e352defc0d9d09031d4b6728840b0a9674e8f (main). Source: github.com/KuangjuX/hypocaust.

SBOM components39
Open findings38
Critical / high0 / 1
Evidence items43

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings (top 25 of 38)

SeverityFindingComponentFixed in
HIGHGHSA-crf7-fvjx-863qzero@0.1.3
MEDIUMLicense not observedzerocopy-derive
MEDIUMLicense not observedzerocopy
MEDIUMLicense not observedzero
MEDIUMLicense not observedxmas-elf
MEDIUMLicense not observedvirtio-drivers
MEDIUMLicense not observedunicode-ident
MEDIUMLicense not observedsyn
MEDIUMLicense not observedstatic_assertions
MEDIUMLicense not observedspin
MEDIUMLicense not observedsemver-parser
MEDIUMLicense not observedsemver
MEDIUMLicense not observedscopeguard
MEDIUMLicense not observedsbi-spec
MEDIUMLicense not observedsbi-rt
MEDIUMLicense not observedrustc_version
MEDIUMLicense not observedriscv-target
MEDIUMLicense not observedriscv-decode
MEDIUMLicense not observedriscv
MEDIUMLicense not observedregex-syntax
MEDIUMLicense not observedregex
MEDIUMLicense not observedquote
MEDIUMLicense not observedproc-macro2
MEDIUMLicense not observedmemchr
MEDIUMLicense not observedlog

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy