SBOM

Core platform components and scanners · session state from seed

Session state · seed

This inventory is the seeded SERF package-gate ledger held in session memory. Click any component row below to open detailed SBOM metadata and CVE analysis.

Components
6
in session inventory
Verified
4
countersigned on ledger
Fail-closed
2
High/Critical, no exception
Exceptions
0
risk accepted
Critical CVE
1
across inventory
High CVE
2
across inventory
ComponentVersionEcosystemLicenseFindingsVerificationAction
curl8.4.0-1.el9rpmcurl (MIT-style)0C / 0H · 1M / 2LVerified
python-requests2.32.3pypiApache-2.00C / 0H · 0M / 1LVerified
zlib1.2.11-17.el9rpmZlib0C / 1H · 0M / 0LHeld
log4j-core2.14.1mavenApache-2.01C / 1H · 0M / 0LHeld
compliance-trestlemappedrepoApache-2.0cleanVerified
contentmappedrepoBSD-3-ClausecleanVerified

7 total findings across 6 components. A component reads Verified only when it is countersigned on the factory ledger — a fail-closed row is never auto-promoted. Full CVE detail and provenance live on the scan ledger.