Software Passport · public repository

hackjutsu/Lepton

Observed by SPR on 2026-09-13 at commit cf91bffef89ef2ae197bd0a2c55f0683e9b3856b (master). Source: github.com/hackjutsu/Lepton.

SBOM components247
Open findings111
Critical / high0 / 1
Evidence items251

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings (top 25 of 111)

SeverityFindingComponentFixed in
HIGHHard-coded credential assignment
MEDIUMLicense not observedyargs-parser
MEDIUMLicense not observedyargs
MEDIUMLicense not observedy18n
MEDIUMLicense not observedwrap-ansi
MEDIUMLicense not observedwarning
MEDIUMLicense not observedvalid-filename
MEDIUMLicense not observedutil-deprecate
MEDIUMLicense not observedurl-parse
MEDIUMLicense not observedunused-filename
MEDIUMLicense not observeduniversalify
MEDIUMLicense not observeduncontrollable
MEDIUMLicense not observedtslib
MEDIUMLicense not observedtough-cookie
MEDIUMLicense not observedsymbol-tree
MEDIUMLicense not observedstrip-ansi
MEDIUMLicense not observedstring-width
MEDIUMLicense not observedstack-trace
MEDIUMLicense not observedsource-map-js
MEDIUMLicense not observedsort-keys-length
MEDIUMLicense not observedsort-keys
MEDIUMLicense not observedslice-ansi
MEDIUMLicense not observedsecure-keys
MEDIUMLicense not observedsax
MEDIUMLicense not observedrequires-port

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy