Software Passport · public repository

meta-pytorch/tokenizers

Observed by SPR on 2026-09-17 at commit 4f9dc6cd2d4512d1c768ba9f6ee6ccad6d449fff (main). Source: github.com/meta-pytorch/tokenizers.

SBOM components24
Open findings19
Critical / high0 / 1
Evidence items28

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
HIGHGHSA-3936-cmfr-pm3mblack@24.4.2
MEDIUMLicense not observedusort
MEDIUMLicense not observedufmt
MEDIUMLicense not observedtorchfix
MEDIUMLicense not observedpycodestyle
MEDIUMLicense not observedmypy
MEDIUMLicense not observedmccabe
MEDIUMLicense not observedlintrunner-adapters
MEDIUMLicense not observedlintrunner
MEDIUMLicense not observedflake8-pyi
MEDIUMLicense not observedflake8-comprehensions
MEDIUMLicense not observedflake8-bugbear
MEDIUMLicense not observedflake8-breakpoint
MEDIUMLicense not observedflake8
MEDIUMLicense not observedcmakelint
MEDIUMLicense not observedclang-format
MEDIUMLicense not observedblack
UNKNOWNPYSEC-2026-2120black@24.4.2
UNKNOWNPYSEC-2026-2121black@24.4.2

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy