Software Passport · public repository

oak-security/cosmwasm-ctf

Observed by SPR on 2026-09-19 at commit c32fa94947f4199596d26696afeb3de0ab3d9cca (main). Source: github.com/oak-security/cosmwasm-ctf.

SBOM components122
Open findings102
Critical / high0 / 1
Evidence items126

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings (top 25 of 102)

SeverityFindingComponentFixed in
HIGHGHSA-x6fg-f45m-jf5qsemver@1.0.17
MEDIUMLicense not observedzeroize
MEDIUMLicense not observedwasi
MEDIUMLicense not observedversion_check
MEDIUMLicense not observedunicode-ident
MEDIUMLicense not observeduint
MEDIUMLicense not observedtypenum
MEDIUMLicense not observedthiserror-impl
MEDIUMLicense not observedthiserror
MEDIUMLicense not observedsyn
MEDIUMLicense not observedsubtle
MEDIUMLicense not observedstatic_assertions
MEDIUMLicense not observedspki
MEDIUMLicense not observedsignature
MEDIUMLicense not observedsha2
MEDIUMLicense not observedserde_json
MEDIUMLicense not observedserde_derive_internals
MEDIUMLicense not observedserde_derive
MEDIUMLicense not observedserde-json-wasm
MEDIUMLicense not observedserde
MEDIUMLicense not observedsemver
MEDIUMLicense not observedsec1
MEDIUMLicense not observedschemars_derive
MEDIUMLicense not observedschemars
MEDIUMLicense not observedryu

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy