Software Passport · public repository

openraven/magpie

Observed by SPR on 2026-09-22 at commit 734064674425ce199cc4ea44ad53f15727a75323 (main). Source: github.com/openraven/magpie.

SBOM components196
Open findings145
Critical / high0 / 0
Evidence items200

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings (top 25 of 145)

SeverityFindingComponentFixed in
MEDIUMLicense not observedunirest-java
MEDIUMLicense not observedtestcontainers
MEDIUMLicense not observedsts
MEDIUMLicense not observedstoragegateway
MEDIUMLicense not observedsso
MEDIUMLicense not observedssm
MEDIUMLicense not observedsns
MEDIUMLicense not observedslf4j-api
MEDIUMLicense not observedsentry
MEDIUMLicense not observedsecurityhub
MEDIUMLicense not observedsecretsmanager
MEDIUMLicense not observeds3
MEDIUMLicense not observedroute53
MEDIUMLicense not observedreflections
MEDIUMLicense not observedredshift
MEDIUMLicense not observedrds
MEDIUMLicense not observedqldb
MEDIUMLicense not observedprotobuf-java-util
MEDIUMLicense not observedpostgresql
MEDIUMLicense not observedorganizations
MEDIUMLicense not observedneptune
MEDIUMLicense not observedmockito-junit-jupiter
MEDIUMLicense not observedmockito-core
MEDIUMLicense not observedlogback-classic
MEDIUMLicense not observedlocation

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy