Software Passport · public repository

eriwen/smap.js

Observed by SPR on 2026-09-15 at commit 6b7ceae31fee1b94c1b279b0effc607067b63477 (master). Source: github.com/eriwen/smap.js.

SBOM components13
Open findings12
Critical / high0 / 0
Evidence items17

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
MEDIUMLicense not observedslf4j-jdk14
MEDIUMLicense not observedslf4j-api
MEDIUMLicense not observedservlet-api
MEDIUMLicense not observedjetty-util
MEDIUMLicense not observedjetty
MEDIUMLicense not observedgunit
MEDIUMLicense not observedcoverage
MEDIUMLicense not observedcommons-logging
MEDIUMLicense not observedcommons-codec
MEDIUMLicense not observedantlr-runtime
MEDIUMLicense not observedantlr
UNKNOWNMAL-2025-6125slf4j-api@1.5.6

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy