Software Passport · public repository

M1r0er/moshen

Observed by SPR on 2026-09-19 at commit ab1700f2229fe4172117dda839fc7b46f965fd38 (main). Source: github.com/M1r0er/moshen.

SBOM components11
Open findings14
Critical / high0 / 2
Evidence items15

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
HIGHStatic API key-like configuration
HIGHHard-coded credential assignment
MEDIUMLicense not observeduvicorn
MEDIUMLicense not observedsse-starlette
MEDIUMLicense not observedpython-multipart
MEDIUMLicense not observedpython-dotenv
MEDIUMLicense not observedpydantic-settings
MEDIUMLicense not observedpydantic
MEDIUMLicense not observedhttpx
MEDIUMLicense not observedfastapi
MEDIUMLicense not observedchardet
MEDIUMLicense not observedaiofiles
UNKNOWNGHSA-mf9w-mj56-hr94python-dotenv@1.0.1
UNKNOWNPYSEC-2026-2270python-dotenv@1.0.1

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy