Software Passport · public repository

grosser/bundler-organization_audit

Observed by SPR on 2026-09-16 at commit 635ef3d470fe7c8e94c2c144db6f1ebd6fe36766 (master). Source: github.com/grosser/bundler-organization_audit.

SBOM components12
Open findings13
Critical / high0 / 1
Evidence items16

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
HIGHGHSA-3c6g-pvg8-gqw2json@2.0.2
MEDIUMLicense not observedthor
MEDIUMLicense not observedrspec-mocks
MEDIUMLicense not observedrspec-expectations
MEDIUMLicense not observedrspec-core
MEDIUMLicense not observedrspec
MEDIUMLicense not observedrake
MEDIUMLicense not observedorganization_audit
MEDIUMLicense not observedjson
MEDIUMLicense not observeddiff-lcs
MEDIUMLicense not observedbundler-organization_audit
MEDIUMLicense not observedbundler-audit
MEDIUMLicense not observedbump

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy