Software Passport · public repository

stefanpenner/es6-promise

Observed by SPR on 2026-09-13 at commit f97e2666e6928745c450752e74213d2438b48b4c (master). Source: github.com/stefanpenner/es6-promise.

SBOM components12
Open findings16
Critical / high0 / 3
Evidence items16

What was observed

Syft generated the software bill of materials from the repository's manifests; each component was checked against the OSV vulnerability database; the tree was scanned for secrets, infrastructure-as-code issues and licence signals. Vendor-supplied attestations: none — this page contains only independent observation.

Open findings

SeverityFindingComponentFixed in
HIGHGHSA-mh99-v99m-4gvgbrace-expansion@1.1.8
HIGHGHSA-3jxr-9vmj-r5cpbrace-expansion@1.1.8
HIGHGHSA-rgw5-rvv9-x895brace-expansion@1.1.8
MEDIUMLicense not observedklaw
MEDIUMLicense not observedhe
MEDIUMLicense not observedhas-ansi
MEDIUMLicense not observedgraceful-readlink
MEDIUMLicense not observedfs.realpath
MEDIUMLicense not observedexit-hook
MEDIUMLicense not observedconcat-map
MEDIUMLicense not observedcode-point-at
MEDIUMLicense not observedbrowser-stdout
MEDIUMLicense not observedbrace-expansion
MEDIUMLicense not observedbalanced-match
LOWGHSA-v6h2-p8h4-qcjwbrace-expansion@1.1.8
UNKNOWNGHSA-f886-m6hf-6m8vbrace-expansion@1.1.8

Get the full passport

Continuous verification, evidence ledger, plain-English and auditor reports, and a shareable signed passport are available to SPR customers.

See plans   Review your own repository free

Software Passport Registry Ltd. Every number on this page was observed by SPR's own scan of the public repository at the commit shown; nothing is estimated or vendor-supplied. Absence of a finding is not proof of safety. Terms · Privacy