Software Passport · public repository

Z4nzu/hackingtool

Observed by SPR on 2026-09-11 at commit ef5334f8d37e5be2eecbf56e334f5e3f0f6817ec (master). Source: github.com/Z4nzu/hackingtool.

SBOM components13
Open findings17
Critical / high0 / 2
Evidence items17

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
HIGHHard-coded credential assignment
HIGHGitHub token-like credential
MEDIUMLicense not observed.github/workflows/release.yml
MEDIUMLicense not observed.github/workflows/checks.yml
MEDIUMLicense not observedsoftprops/action-gh-release
MEDIUMLicense not observedpypa/gh-action-pypi-publish
MEDIUMLicense not observeddocker/setup-buildx-action
MEDIUMLicense not observeddocker/metadata-action
MEDIUMLicense not observeddocker/login-action
MEDIUMLicense not observeddocker/build-push-action
MEDIUMLicense not observedastral-sh/setup-uv
MEDIUMLicense not observedactions/upload-artifact
MEDIUMLicense not observedactions/setup-python
MEDIUMLicense not observedactions/download-artifact
MEDIUMLicense not observedactions/checkout
MEDIUMLicense not observedactions/attest-sbom
MEDIUMLicense not observedactions/attest-build-provenance

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy