Software Passport · public repository

Synvoya/codeinspectus

Observed by SPR on 2026-09-21 at commit 589cee43f0a254cd908d7925a3daf5135aa0388f (master). Source: github.com/Synvoya/codeinspectus.

SBOM components150
Open findings135
Critical / high5 / 19
Evidence items151

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings (top 25 of 135)

SeverityFindingComponentFixed in
CRITICALGHSA-frmv-pr5f-9mcrdjango@5.2.5
CRITICALGHSA-xvch-5gv4-984hminimist@1.2.0
CRITICALGHSA-jf85-cpcp-j695lodash@4.17.4
CRITICALPrivate key material
CRITICALStripe live secret-like credential
HIGHGHSA-wqp7-x3pw-xc5rstarlette@0.47.2
HIGHGHSA-82w8-qh3p-5jfqstarlette@0.47.2
HIGHGHSA-7f5h-v6xp-fcq8starlette@0.47.2
HIGHGHSA-933h-hp56-hf7mdjango@5.2.5
HIGHGHSA-mvfq-ggxm-9mc5django@5.2.5
HIGHGHSA-qw25-v68c-qjf3django@5.2.5
HIGHGHSA-hpr9-3m2g-3j9pdjango@5.2.5
HIGHGHSA-mwm9-4648-f68qdjango@5.2.5
HIGHGHSA-gvg8-93h5-g6qqdjango@5.2.5
HIGHGHSA-6w2r-r2m5-xq5wdjango@5.2.5
HIGHGHSA-8p8v-wh79-9r56django@5.2.5
HIGHGHSA-4xc9-xhrj-v574lodash@4.17.4
HIGHGHSA-p6mc-m468-83gwlodash@4.17.4
HIGHGHSA-r5fr-rjxr-66jclodash@4.17.4
HIGHGHSA-35jh-r3h4-6jhmlodash@4.17.4
HIGHGoogle API key-like credential
HIGHGitHub token-like credential
HIGHAWS access key identifier
HIGHHard-coded credential assignment
MEDIUMLicense not observedvulnerable-app

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy