Software Passport · public repository
matsumo0922/Kanade
Observed by SPR on 2026-09-16 at commit 815614953be0599d8f1be3c71f554cdd65db9ba1 (master). Source: github.com/matsumo0922/Kanade.
What was observed
Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.
Open findings
| Severity | Finding | Component | Fixed in |
|---|---|---|---|
| HIGH | Static API key-like configuration | ||
| HIGH | Google API key-like credential | ||
| MEDIUM | License not observed | gradle-wrapper | |
| MEDIUM | License not observed | ./.github/workflows/call-lint.yml | |
| MEDIUM | License not observed | ./.github/workflows/call-build.yml |
Get the full passport
Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.
See plans Review your own repository freeSoftware Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy