Software Passport · public repository

dylanjha/snitch

Observed by SPR on 2026-09-17 at commit 499d192fc98b8e288db94713fbf72012a4e823a6 (master). Source: github.com/dylanjha/snitch.

SBOM components31
Open findings37
Critical / high0 / 1
Evidence items35

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings (top 25 of 37)

SeverityFindingComponentFixed in
HIGHGHSA-wrvr-8mpx-r7ppmime@1.3.1
MEDIUMLicense not observedtesla
MEDIUMLicense not observedtelemetry
MEDIUMLicense not observedslugger
MEDIUMLicense not observedranch
MEDIUMLicense not observedpostgrex
MEDIUMLicense not observedplug_crypto
MEDIUMLicense not observedplug_cowboy
MEDIUMLicense not observedplug
MEDIUMLicense not observedphoenix_pubsub
MEDIUMLicense not observedphoenix_live_view
MEDIUMLicense not observedphoenix_live_reload
MEDIUMLicense not observedphoenix_html
MEDIUMLicense not observedphoenix_ecto
MEDIUMLicense not observedphoenix
MEDIUMLicense not observedmux
MEDIUMLicense not observedmime
MEDIUMLicense not observedjose
MEDIUMLicense not observedjason
MEDIUMLicense not observedgettext
MEDIUMLicense not observedfile_system
MEDIUMLicense not observedecto_sql
MEDIUMLicense not observedecto
MEDIUMLicense not observeddecimal
MEDIUMLicense not observeddb_connection

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy