Software Passport · public repository

esimov/caire

Observed by SPR on 2026-09-22 at commit 072a5888af55502d89b07157613be885cca14156 (master). Source: github.com/esimov/caire.

SBOM components19
Open findings16
Critical / high0 / 0
Evidence items23

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
MEDIUMLicense not observedgopkg.in/yaml.v3
MEDIUMLicense not observedgopkg.in/check.v1
MEDIUMLicense not observedgolang.org/x/text
MEDIUMLicense not observedgolang.org/x/term
MEDIUMLicense not observedgolang.org/x/sys
MEDIUMLicense not observedgolang.org/x/image
MEDIUMLicense not observedgolang.org/x/exp/shiny
MEDIUMLicense not observedgolang.org/x/exp
MEDIUMLicense not observedgithub.com/stretchr/testify
MEDIUMLicense not observedgithub.com/pmezard/go-difflib
MEDIUMLicense not observedgithub.com/go-text/typesetting
MEDIUMLicense not observedgithub.com/esimov/pigo
MEDIUMLicense not observedgithub.com/disintegration/imaging
MEDIUMLicense not observedgithub.com/davecgh/go-spew
MEDIUMLicense not observedgioui.org/shader
MEDIUMLicense not observedgioui.org

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy