SBOM
Core platform components and scanners · session state from seed
Data as of23 Aug 2026
Session state · seed
This inventory is the seeded SERF package-gate ledger held in session memory. Click any component row below to open detailed SBOM metadata and CVE analysis.
- Components
- 6 in session inventory
- Verified
- 4 countersigned on ledger
- Fail-closed
- 2 High/Critical, no exception
- Exceptions
- 0 risk accepted
- Critical CVE
- 1 across inventory
- High CVE
- 2 across inventory
| Component | Version | Ecosystem | License | Findings | Verification | Action |
|---|---|---|---|---|---|---|
| curl | 8.4.0-1.el9 | rpm | curl (MIT-style) | 0C / 0H · 1M / 2L | Verified | |
| python-requests | 2.32.3 | pypi | Apache-2.0 | 0C / 0H · 0M / 1L | Verified | |
| zlib | 1.2.11-17.el9 | rpm | Zlib | 0C / 1H · 0M / 0L | Held | |
| log4j-core | 2.14.1 | maven | Apache-2.0 | 1C / 1H · 0M / 0L | Held | |
| compliance-trestle | mapped | repo | Apache-2.0 | clean | Verified | |
| content | mapped | repo | BSD-3-Clause | clean | Verified |
7 total findings across 6 components. A component reads Verified only when it is countersigned on the factory ledger — a fail-closed row is never auto-promoted. Full CVE detail and provenance live on the scan ledger.