Software Passport · public repository

lowspeclabs/SmallCTL

Observed by SPR on 2026-09-18 at commit 1ce1cb556e9c0a2fe95a5bb5c6bb0287823f33b6 (main). Source: github.com/lowspeclabs/SmallCTL.

SBOM components63
Open findings67
Critical / high0 / 4
Evidence items67

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings (top 25 of 67)

SeverityFindingComponentFixed in
HIGHGHSA-f4xh-w4cj-qxq8langsmith@0.8.8
HIGHStatic API key-like configuration
HIGHGitHub token-like credential
HIGHHard-coded credential assignment
MEDIUMLicense not observedzstandard
MEDIUMLicense not observedxxhash
MEDIUMLicense not observedwebsockets
MEDIUMLicense not observeduuid-utils
MEDIUMLicense not observedurllib3
MEDIUMLicense not observeduc-micro-py
MEDIUMLicense not observedtyping-inspection
MEDIUMLicense not observedtyping-extensions
MEDIUMLicense not observedtomli
MEDIUMLicense not observedtextual
MEDIUMLicense not observedtenacity
MEDIUMLicense not observedsmallctl
MEDIUMLicense not observedruff
MEDIUMLicense not observedrich
MEDIUMLicense not observedrequests-toolbelt
MEDIUMLicense not observedrequests
MEDIUMLicense not observedpyyaml-ft
MEDIUMLicense not observedpyyaml
MEDIUMLicense not observedpython-debian
MEDIUMLicense not observedpytest-xdist
MEDIUMLicense not observedpytest-asyncio

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy