Software Passport · public repository

smicallef/spiderfoot

Observed by SPR on 2026-09-25 at commit 0f815a203afebf05c98b605dba5cf0475a0ee5fd (master). Source: github.com/smicallef/spiderfoot.

SBOM components23
Open findings21
Critical / high0 / 2
Evidence items27

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
HIGHStatic API key-like configuration
HIGHHard-coded credential assignment
MEDIUMLicense not observedresponses
MEDIUMLicense not observedpytest-xdist
MEDIUMLicense not observedpytest-mock
MEDIUMLicense not observedpytest-cov
MEDIUMLicense not observedpytest
MEDIUMLicense not observedpycodestyle
MEDIUMLicense not observedflake8-simplify
MEDIUMLicense not observedflake8-sfs
MEDIUMLicense not observedflake8-return
MEDIUMLicense not observedflake8-quotes
MEDIUMLicense not observedflake8-builtins
MEDIUMLicense not observedflake8-bugbear
MEDIUMLicense not observedflake8-blind-except
MEDIUMLicense not observedflake8-annotations
MEDIUMLicense not observedflake8
MEDIUMLicense not observeddlint
MEDIUMLicense not observeddarglint
UNKNOWNPYSEC-2026-1845pytest@7.2.1
UNKNOWNGHSA-6w46-j5rx-g56gpytest@7.2.1

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy