Software Passport · public repository

cobbr/Covenant

Observed by SPR on 2026-09-23 at commit 5decc3ccfab04e6e881ed00c9de649740dac8ad1 (master). Source: github.com/cobbr/Covenant.

SBOM components32
Open findings19
Critical / high0 / 2
Evidence items36

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
HIGHStatic API key-like configuration
HIGHHard-coded credential assignment
MEDIUMLicense not observeddnlib
MEDIUMLicense not observedSystem.Web.Extensions.dll
MEDIUMLicense not observedSystem.Security.dll
MEDIUMLicense not observedSystem.Management.Automation
MEDIUMLicense not observedSystem.IdentityModel.dll
MEDIUMLicense not observedSharpSploit.Resources.powerkatz_x86
MEDIUMLicense not observedSharpSploit.Resources.powerkatz_x64
MEDIUMLicense not observedPeNet
MEDIUMLicense not observedMicrosoft Common Language Runtime Class Library
MEDIUMLicense not observedDonut.dll
MEDIUMLicense not observedConfuser.Runtime
MEDIUMLicense not observedConfuser.Renamer
MEDIUMLicense not observedConfuser.Protections
MEDIUMLicense not observedConfuser.MSBuild.Tasks
MEDIUMLicense not observedConfuser.DynCipher
MEDIUMLicense not observedConfuser.Core
MEDIUMLicense not observed.NET Framework

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy