Software Passport · public repository

envkey/envkey-ruby

Observed by SPR on 2026-09-26 at commit 0ebecfd9b8daa91d7e607c5684dd628a25b8ff2f (master). Source: github.com/envkey/envkey-ruby.

SBOM components12
Open findings10
Critical / high0 / 0
Evidence items16
Maintain envkey/envkey-ruby?

Claim this passport: run your own review of the latest commit and get an SBOM and vulnerability report you can hand to customers who ask for one. Free to start.

Claim this passport

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
MEDIUMLicense not observedgolang.org/x/crypto
MEDIUMLicense not observedgithub.com/spf13/pflag
MEDIUMLicense not observedgithub.com/spf13/cobra
MEDIUMLicense not observedgithub.com/mitchellh/go-homedir
MEDIUMLicense not observedgithub.com/inconshreveable/mousetrap
MEDIUMLicense not observedgithub.com/hashicorp/go-multierror
MEDIUMLicense not observedgithub.com/hashicorp/errwrap
MEDIUMLicense not observedgithub.com/envkey/envkey-fetch
MEDIUMLicense not observedgithub.com/certifi/gocertifi
MEDIUMLicense not observedenvkey-fetch

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy